This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virtumonde and other Trojans

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The infection just got worse.
Important you do not reboot until instructed to.

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]
  • If shown the disclaimer, Select "2"

Next: We need to get the updated Combofix program

Download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
I got combofix to work …..I'm not touching a thing until I here from you

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:33:38 PM, on 12/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\Spyware.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotwheelscollectors.com/default.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [PCLEUSBTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" -scheduler
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4058/ftp…ver/Coupons.cab
O16 - DPF: {D2349304-8F9E-4A54-ACF6-0F6104B44209} (SketchCtl.Pic1) - http://auditor.cuyahogacounty.us/repi/sketch/Sketch.ocx
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 9021 bytes

ComboFix 07-12-31.4 - Mark 2007-12-31 21:56:23.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.174 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM .exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM .exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\\PSDrvCheck.exe
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\mllmn.dll
C:\WINDOWS\system32\mllmn.exe
C:\WINDOWS\system32\nmllm.ini
C:\WINDOWS\system32\nmllm.ini2
C:\WINDOWS\system32\PSDrvCheck.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2G1.EXE
C:\WINDOWS\UpdReg.EXE

.
((((((((((((((((((((((((( Files Created from 2007-12-01 to 2008-01-01 )))))))))))))))))))))))))))))))
.

2007-12-31 21:51 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-12-31 17:51 . 2007-12-31 17:51 342,016 –a—— C:\WINDOWS\system32\RCX52.tmp
2007-12-31 16:02 . 2007-12-31 22:24 362,528 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-31 16:02 . 2007-12-31 22:20 5,300 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-31 15:57 . 2007-12-31 15:57 d——– C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-12-31 15:28 . 2007-12-31 21:26 406,016 –a—— C:\WINDOWS\system32\PSDrvCheck .exe
2007-12-31 15:28 . 2007-12-31 21:26 114,688 –a—— C:\WINDOWS\system32\igfxpers .exe
2007-12-31 15:28 . 2007-12-31 21:26 94,208 –a—— C:\WINDOWS\system32\igfxtray .exe
2007-12-31 15:28 . 2007-12-31 21:26 90,112 –a—— C:\WINDOWS\UpdReg .EXE
2007-12-31 15:28 . 2007-12-31 21:26 77,824 –a—— C:\WINDOWS\system32\hkcmd .exe
2007-12-31 14:23 . 2007-12-31 21:27 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2007-12-29 08:27 . 2007-12-31 22:22 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-28 17:13 . 2007-12-28 17:22 74,240 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-28 17:13 . 2007-12-28 17:22 56,832 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-28 17:13 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-28 17:13 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-28 17:12 . 2007-12-31 22:13 d——– C:\Program Files\Spyware Doctor
2007-12-28 17:12 . 2007-12-28 17:12 d——– C:\Documents and Settings\Mark\Application Data\PC Tools
2007-12-28 17:11 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-12-28 11:31 . 2007-12-28 11:31 d——– C:\Documents and Settings\Mark\Application Data\Apple Computer
2007-12-28 11:09 . 2007-12-28 11:09 d——– C:\Program Files\Apple Software Update
2007-12-28 11:07 . 2007-12-28 11:07 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-12-28 11:07 . 2007-10-31 14:09 30,464 –a—— C:\WINDOWS\system32\drivers\usbaapl.sys
2007-12-28 11:06 . 2007-12-28 11:06 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-12-27 11:08 . 2005-08-26 12:11 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-12-27 11:08 . 2005-08-26 12:24 d——– C:\Documents and Settings\Administrator\Application Data\Creative
2007-12-26 23:14 . 2007-12-26 23:13 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-12-26 23:13 . 2007-12-26 23:31 d——– C:\Documents and Settings\Mark\.housecall6.6
2007-12-26 22:49 . 2007-12-26 22:49 d——– C:\Program Files\Trend Micro
2007-12-26 13:10 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-12-26 13:10 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-26 13:10 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-26 13:10 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-26 13:10 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-26 13:10 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-26 13:09 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-12-26 13:09 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2007-12-25 09:58 . 2007-12-26 20:14 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-24 10:40 . 2007-12-28 11:29 d——– C:\Program Files\iTunes
2007-12-24 10:40 . 2007-12-24 10:40 d——– C:\Program Files\iPod
2007-12-24 10:30 . 2007-12-26 12:35 d——– C:\Program Files\Apple Software Update(2)
2007-12-24 10:27 . 2007-12-24 10:27 d——– C:\Program Files\Common Files\Apple
2007-12-18 20:48 . 2007-12-18 20:48 d——– C:\Program Files\Logitech
2007-12-18 20:48 . 2007-12-18 20:48 d——– C:\Program Files\Common Files\Logitech
2007-12-18 20:48 . 2005-04-12 19:21 45,504 –a—— C:\WINDOWS\system32\drivers\WmXlCore.sys
2007-12-18 20:48 . 2005-04-12 19:21 22,240 –a—— C:\WINDOWS\system32\drivers\WmFilter.sys
2007-12-18 20:48 . 2005-04-12 19:21 10,144 –a—— C:\WINDOWS\system32\drivers\WmBEnum.sys
2007-12-18 20:48 . 2005-04-12 19:21 5,600 –a—— C:\WINDOWS\system32\drivers\WmVirHid.sys
2007-12-15 22:27 . 2007-12-29 11:34 d——– C:\Program Files\Project64 1.6
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-09 20:59 . 2007-12-10 22:01 d——– C:\Program Files\Azureus
2007-12-09 20:59 . 2007-12-13 16:48 d——– C:\Documents and Settings\Nick\Application Data\Azureus
2007-12-09 20:53 . 2007-12-09 20:53 d——– C:\Downloads

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-01 03:14 ——— d—–w C:\Program Files\DellSupport
2007-12-31 16:30 ——— d—–w C:\Program Files\QuickTime
2007-12-30 21:07 ——— d—–w C:\Program Files\Quicken
2007-12-28 16:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-24 15:42 ——— d—–w C:\Documents and Settings\Nick\Application Data\Apple Computer
2007-12-21 23:58 11,031,348 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-12-21 23:08 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-10 02:45 ——— d—–w C:\Program Files\BitComet
2007-11-30 22:19 ——— d—–w C:\Program Files\IZArc
2007-11-29 00:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Smilebox
2007-11-18 14:05 ——— d—–w C:\Program Files\Java
2007-11-14 21:05 75,248 —-a-w C:\WINDOWS\zllsputility.exe
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-11 22:05 73,216 —-a-w C:\WINDOWS\ST6UNST.EXE
2007-11-03 20:13 ——— d—–w C:\Program Files\Fire International
2007-11-03 13:52 49,827 —-a-w C:\Uninstal.exe
2002-07-26 21:02 153,088 —-a-w C:\Program Files\UNWISE.EXE
2007-09-27 02:35 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
—-a-w			39,792 2008-01-01 02:26:56  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w			79,224 2008-01-01 02:26:57  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
—-a-w		 2,321,600 2008-01-01 02:27:36  C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater .exe
—-a-w			86,960 2008-01-01 02:26:17  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		   218,032 2007-12-31 22:52:16  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM   .exe
—-a-w			57,344 2008-01-01 02:26:01  C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol .exe
—-a-w			32,768 2008-01-01 02:26:49  C:\Program Files\CyberLink\PowerDVD\PDVDServ .exe
—-a-w			86,016 2008-01-01 02:26:19  C:\Program Files\Dell\Media Experience\DMXLauncher .exe
—-a-w		   460,784 2008-01-01 02:27:27  C:\Program Files\DellSupport\DSAgnt .exe
—-a-w		   221,184 2008-01-01 02:26:01  C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
—-a-w		   132,496 2008-01-01 02:25:58  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		 1,694,208 2008-01-01 02:48:44  C:\Program Files\Messenger\msmsgs .exe
—-a-w			53,248 2008-01-01 02:26:11  C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask .exe
—-a-w		   131,072 2008-01-01 02:26:09  C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray .exe
—-a-w		   196,608 2008-01-01 02:26:45  C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip .exe
—-a-w			26,112 2008-01-01 02:26:27  C:\Program Files\Real\RealPlayer\RealPlay .exe
—-a-w		 1,460,560 2008-01-01 02:27:34  C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
—-a-w		 1,065,800 2008-01-01 02:27:08  C:\Program Files\Spyware Doctor\SDTrayApp .exe
—-a-w		   919,280 2007-12-31 20:29:19  C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
—-a-w			90,112 2008-01-01 02:26:06  C:\WINDOWS\UpdReg .EXE
—-a-w			15,360 2008-01-01 02:27:31  C:\WINDOWS\system32\ctfmon .exe
—-a-w			77,824 2008-01-01 02:26:25  C:\WINDOWS\system32\hkcmd .exe
—-a-w		   114,688 2008-01-01 02:26:31  C:\WINDOWS\system32\igfxpers .exe
—-a-w			94,208 2008-01-01 02:26:24  C:\WINDOWS\system32\igfxtray .exe
—-a-w		   406,016 2008-01-01 02:26:37  C:\WINDOWS\system32\PSDrvCheck .exe
—-a-w		   122,941 2008-01-01 02:26:53  C:\WINDOWS\system32\dla\tfswctrl .exe
—-a-w			99,840 2008-01-01 02:26:21  C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2G1 .EXE


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-12-30 16:43 15360]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" [ ]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [ ]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [ ]
"CTSysVol"="C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [ ]
"P17Helper"="P17.dll" [2004-06-10 16:51 60928 C:\WINDOWS\system32\P17.dll]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [ ]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [ ]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [ ]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [ ]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [ ]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [ ]
"EPSON Stylus CX5400"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.exe" [ ]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [ ]
"PinnacleDriverCheck"="C:\WINDOWS\system32\\PSDrvCheck.exe" [ ]
"PCLEUSBTip"="C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe" [ ]
"USB2Check"="C:\WINDOWS\system32\PCLECoInst.dll" [2005-12-21 09:14 73728]
"USBToolTip"="C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [ ]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [ ]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [ ]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" [ ]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [ ]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]

C:\Documents and Settings\Nick\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2003-09-25 09:47:12]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Dataviz Messenger.lnk - C:\WINDOWS\DvzCommon\DvzMsgr.exe [2003-07-01 20:16:46]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 11:59:36]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - C:\Program Files\WiFiConnector\NintendoWFCReg.exe [2006-12-25 22:11:14]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""


.
Contents of the 'Scheduled Tasks' folder
"2007-12-29 17:23:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-01 01:39:43 C:\WINDOWS\Tasks\User_Feed_Synchronization-{50D0D4BC-426E-44B2-9BFA-DEE6413827B3}.job"
- C:\WINDOWS\system32\msfeedssync.exe
"2008-01-01 01:43:45 C:\WINDOWS\Tasks\User_Feed_Synchronization-{92AE00CF-95FA-45D4-8547-820AEBE39993}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-31 22:23:19
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\Program Files\ArcSoft\Software Suite\PhotoImpression 5\share\pihook.dll
.
Completion time: 2007-12-31 22:32:13 - machine was rebooted
C:\qoobox\ComboFix-quarantined-files.txt 2008-01-01 03:32:03
C:\qoobox\ComboFix2.txt 2007-12-31 22:08:04
C:\qoobox\ComboFix3.txt 2007-12-31 18:59:57
C:\qoobox\ComboFix4.txt 2007-12-29 13:38:56
.
2007-12-27 12:33:26 — E O F —
1.) Copy the following text to a new notepad file.
Save it as CFScript.txt but do NOT use it yet.

  • Copy the entire contents of the Code Box below to Notepad.
  • Name the file as CFScript.txt (Overwrite the existing one)
  • Change the Save as Type to All Files
  • and Save it on the desktop
file::
C:\WINDOWS\system32\RCX52.tmp
C:\WINDOWS\system32\igfxpers .exe
C:\WINDOWS\system32\igfxtray .exe
C:\WINDOWS\UpdReg .EXE
C:\WINDOWS\system32\hkcmd .exe
C:\WINDOWS\system32\ctfmon .exe

2.) Drag log.txt from desktop that RenV created on top of RenV.exe
Follow the prompts.
Once done it makes a log.
Post its results.

3.) Drag CFScript on top of combofix.exe and let it run.
Post the new log it makes when machine reboots.

Let me know how machine is running.
Ran on Tue 01/01/2008 -  9:15:16.79

——w			79,224 2008-01-01 02:26:57  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
——w		   919,280 2007-12-31 20:29:19  C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe

 Entries:				2  (2)
 Directories:			0  Files:			 2
 Bytes:			998,504  Blocks:		1,951

ComboFix 07-12-31.4 - Mark 2008-01-01 9:21:09.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.195 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mark\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\ctfmon .exe
C:\WINDOWS\system32\hkcmd .exe
C:\WINDOWS\system32\igfxpers .exe
C:\WINDOWS\system32\igfxtray .exe
C:\WINDOWS\system32\RCX52.tmp
C:\WINDOWS\UpdReg .EXE
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\RCX52.tmp

.
((((((((((((((((((((((((( Files Created from 2007-12-01 to 2008-01-01 )))))))))))))))))))))))))))))))
.

2008-01-01 09:15 . 2007-12-31 21:26 406,016 –a—— C:\WINDOWS\system32\PSDrvCheck.exe
2008-01-01 09:15 . 2007-12-31 21:26 114,688 –a—— C:\WINDOWS\system32\igfxpers.exe
2008-01-01 09:15 . 2007-12-31 21:26 94,208 –a—— C:\WINDOWS\system32\igfxtray.exe
2008-01-01 09:15 . 2007-12-31 21:26 90,112 –a—— C:\WINDOWS\UpdReg.EXE
2008-01-01 09:15 . 2007-12-31 21:26 77,824 –a—— C:\WINDOWS\system32\hkcmd.exe
2007-12-31 21:51 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-12-31 16:02 . 2008-01-01 09:28 428,064 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-31 16:02 . 2007-12-31 22:36 5,444 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-31 15:57 . 2007-12-31 15:57 d——– C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-12-29 08:27 . 2007-12-31 22:37 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-28 17:13 . 2007-12-28 17:22 74,240 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-28 17:13 . 2007-12-28 17:22 56,832 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-28 17:13 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-28 17:13 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-28 17:12 . 2008-01-01 09:15 d——– C:\Program Files\Spyware Doctor
2007-12-28 17:12 . 2007-12-28 17:12 d——– C:\Documents and Settings\Mark\Application Data\PC Tools
2007-12-28 17:11 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-12-28 11:31 . 2007-12-28 11:31 d——– C:\Documents and Settings\Mark\Application Data\Apple Computer
2007-12-28 11:09 . 2007-12-28 11:09 d——– C:\Program Files\Apple Software Update
2007-12-28 11:07 . 2007-12-28 11:07 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-12-28 11:07 . 2007-10-31 14:09 30,464 –a—— C:\WINDOWS\system32\drivers\usbaapl.sys
2007-12-28 11:06 . 2007-12-28 11:06 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-12-27 11:08 . 2005-08-26 12:11 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-12-27 11:08 . 2005-08-26 12:24 d——– C:\Documents and Settings\Administrator\Application Data\Creative
2007-12-26 23:14 . 2007-12-26 23:13 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-12-26 23:13 . 2007-12-26 23:31 d——– C:\Documents and Settings\Mark\.housecall6.6
2007-12-26 22:49 . 2007-12-26 22:49 d——– C:\Program Files\Trend Micro
2007-12-26 13:10 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-12-26 13:10 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-26 13:10 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-26 13:10 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-26 13:10 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-26 13:10 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-26 13:09 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-12-26 13:09 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2007-12-25 09:58 . 2007-12-26 20:14 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-24 10:40 . 2007-12-28 11:29 d——– C:\Program Files\iTunes
2007-12-24 10:40 . 2007-12-24 10:40 d——– C:\Program Files\iPod
2007-12-24 10:30 . 2007-12-26 12:35 d——– C:\Program Files\Apple Software Update(2)
2007-12-24 10:27 . 2007-12-24 10:27 d——– C:\Program Files\Common Files\Apple
2007-12-18 20:48 . 2007-12-18 20:48 d——– C:\Program Files\Logitech
2007-12-18 20:48 . 2007-12-18 20:48 d——– C:\Program Files\Common Files\Logitech
2007-12-18 20:48 . 2005-04-12 19:21 45,504 –a—— C:\WINDOWS\system32\drivers\WmXlCore.sys
2007-12-18 20:48 . 2005-04-12 19:21 22,240 –a—— C:\WINDOWS\system32\drivers\WmFilter.sys
2007-12-18 20:48 . 2005-04-12 19:21 10,144 –a—— C:\WINDOWS\system32\drivers\WmBEnum.sys
2007-12-18 20:48 . 2005-04-12 19:21 5,600 –a—— C:\WINDOWS\system32\drivers\WmVirHid.sys
2007-12-15 22:27 . 2007-12-29 11:34 d——– C:\Program Files\Project64 1.6
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-09 20:59 . 2007-12-10 22:01 d——– C:\Program Files\Azureus
2007-12-09 20:59 . 2007-12-13 16:48 d——– C:\Documents and Settings\Nick\Application Data\Azureus
2007-12-09 20:53 . 2007-12-09 20:53 d——– C:\Downloads

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-01 14:15 ——— d—–w C:\Program Files\QuickTime
2008-01-01 14:15 ——— d—–w C:\Program Files\DellSupport
2008-01-01 02:27 15,360 —-a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-01-01 02:27 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
2007-12-30 21:07 ——— d—–w C:\Program Files\Quicken
2007-12-28 16:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-24 15:42 ——— d—–w C:\Documents and Settings\Nick\Application Data\Apple Computer
2007-12-21 23:58 11,031,348 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-12-21 23:08 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-10 02:45 ——— d—–w C:\Program Files\BitComet
2007-11-30 22:19 ——— d—–w C:\Program Files\IZArc
2007-11-29 00:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Smilebox
2007-11-18 14:05 ——— d—–w C:\Program Files\Java
2007-11-14 21:05 75,248 —-a-w C:\WINDOWS\zllsputility.exe
2007-11-14 21:05 1,086,952 —-a-w C:\WINDOWS\system32\zpeng24.dll
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-11 22:05 73,216 —-a-w C:\WINDOWS\ST6UNST.EXE
2007-11-11 22:04 19,659,826 —-a-w C:\WINDOWS\system32\lebronjames0607.scr
2007-11-03 20:13 ——— d—–w C:\Program Files\Fire International
2007-11-03 13:52 49,827 —-a-w C:\Uninstal.exe
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ——w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ——w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ——w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ——w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ——w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ——w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ——w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ——w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2002-07-26 21:02 153,088 —-a-w C:\Program Files\UNWISE.EXE
2007-09-27 02:35 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
——w			79,224 2008-01-01 02:26:57  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
——w		   919,280 2007-12-31 20:29:19  C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe


((((((((((((((((((((((((((((( snapshot@2007-12-31_22.31.10.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-01 02:26:53 122,941 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
+ 2008-01-01 02:26:21 99,840 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2G1.EXE
+ 2008-01-01 03:36:58 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_69c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2007-12-31 21:48 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-12-31 21:27 15360]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" [ ]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-12-31 21:27 460784]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-12-31 21:27 2321600]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-12-31 21:27 1460560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-12-31 21:25 132496]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2007-12-31 21:26 221184]
"CTSysVol"="C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2007-12-31 21:26 57344]
"P17Helper"="P17.dll" [2004-06-10 16:51 60928 C:\WINDOWS\system32\P17.dll]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2007-12-31 21:26 90112]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2007-12-31 21:26 131072]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2007-12-31 21:26 53248]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2007-12-31 21:26 26112]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2007-12-31 21:26 86960]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2007-12-31 21:26 86016]
"EPSON Stylus CX5400"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.exe" [2007-12-31 21:26 99840]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2007-12-31 21:26 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2007-12-31 21:26 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2007-12-31 21:26 114688]
"PinnacleDriverCheck"="C:\WINDOWS\system32\\PSDrvCheck.exe" [2007-12-31 21:26 406016]
"PCLEUSBTip"="C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe" [2007-12-31 21:26 196608]
"USB2Check"="C:\WINDOWS\system32\PCLECoInst.dll" [2005-12-21 09:14 73728]
"USBToolTip"="C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [2007-12-31 21:26 196608]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-12-31 21:26 32768]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2007-12-31 21:26 122941]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-12-31 21:26 39792]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" [ ]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-12-31 21:27 1065800]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]

C:\Documents and Settings\Nick\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2003-09-25 09:47:12]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Dataviz Messenger.lnk - C:\WINDOWS\DvzCommon\DvzMsgr.exe [2003-07-01 20:16:46]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 11:59:36]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - C:\Program Files\WiFiConnector\NintendoWFCReg.exe [2006-12-25 22:11:14]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""


.
Contents of the 'Scheduled Tasks' folder
"2007-12-29 17:23:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-01 14:28:00 C:\WINDOWS\Tasks\User_Feed_Synchronization-{50D0D4BC-426E-44B2-9BFA-DEE6413827B3}.job"
- C:\WINDOWS\system32\msfeedssync.exe
"2008-01-01 04:00:14 C:\WINDOWS\Tasks\User_Feed_Synchronization-{92AE00CF-95FA-45D4-8547-820AEBE39993}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-01 09:28:24
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-01 9:30:03
C:\qoobox\ComboFix-quarantined-files.txt 2008-01-01 14:29:50
C:\qoobox\ComboFix2.txt 2008-01-01 03:32:14
C:\qoobox\ComboFix3.txt 2007-12-31 22:08:04
C:\qoobox\ComboFix4.txt 2007-12-31 18:59:57
C:\qoobox\ComboFix5.txt 2007-12-29 13:38:56
.
2007-12-27 12:33:26 — E O F —

pc is fast again thanks

should I run Spyware Dr. ? :blush:
Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Tuesday, January 01, 2008 12:11:40 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 1/01/2008 Kaspersky Anti-Virus database records: 501052 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ Scan Statistics: Total number of scanned objects: 116113 Number of viruses found: 4 Number of infected objects: 122 Number of suspicious objects: 2 Duration of the scan process: 01:44:16 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip/Yazzle1552OinUninstaller.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\temp\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\temp\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Mark\Application Data\Sun\Java\Deployment\cache\6.0\43\59a44f6b-3ed1c321/BaaaaBaa.class Infected: Trojan.Java.ClassLoader.ao skipped C:\Documents and Settings\Mark\Application Data\Sun\Java\Deployment\cache\6.0\43\59a44f6b-3ed1c321/VaaaaaaaBaa.class Infected: Trojan.Java.ClassLoader.ao skipped C:\Documents and Settings\Mark\Application Data\Sun\Java\Deployment\cache\6.0\43\59a44f6b-3ed1c321/Baaaaa.class Infected: Trojan.Java.ClassLoader.ao skipped C:\Documents and Settings\Mark\Application Data\Sun\Java\Deployment\cache\6.0\43\59a44f6b-3ed1c321 ZIP: infected - 3 skipped C:\Documents and Settings\Mark\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Mark\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Mark\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Mark\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Mark\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Mark\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Mark\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Nick\Application Data\Sun\Java\Deployment\cache\6.0\49\49820371-6b4f0c27/vmain.class Infected: Exploit.Java.Gimsh.b skipped C:\Documents and Settings\Nick\Application Data\Sun\Java\Deployment\cache\6.0\49\49820371-6b4f0c27 ZIP: infected - 1 skipped C:\Documents and Settings\Nick\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-5efd1945-3532dc6b.zip/vmain.class Infected: Exploit.Java.Gimsh.b skipped C:\Documents and Settings\Nick\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-5efd1945-3532dc6b.zip ZIP: infected - 1 skipped C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped C:\QooBox\Quarantine\C\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\Common Files\InstallShield\UpdateService\issch.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM .exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\CyberLink\PowerDVD\PDVDServ.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\Dell\Media Experience\DMXLauncher.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\DellSupport\DSAgnt.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\Intel\Modem Event Monitor\IntelMEM.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\Java\jre1.6.0_03\bin\jusched.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\Messenger\msmsgs.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\Real\RealPlayer\RealPlay.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\Spybot - Search & Destroy\TeaTimer.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\Program Files\Spyware Doctor\SDTrayApp.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\WINDOWS\system32\ctfmon.exe.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\WINDOWS\system32\dla\tfswctrl.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\WINDOWS\system32\hkcmd.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\WINDOWS\system32\igfxpers.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\WINDOWS\system32\igfxtray.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\WINDOWS\system32\mllmn.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\WINDOWS\system32\PSDrvCheck.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\WINDOWS\system32\RCX52.tmp.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2G1.EXE.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\QooBox\Quarantine\C\WINDOWS\UpdReg.EXE.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178889.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178893.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178895.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178896.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178898.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178899.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178900.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178901.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178902.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178903.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178904.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178905.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178906.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178907.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178908.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178909.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178910.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178911.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178912.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178913.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178914.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178915.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178916.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178917.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178918.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178919.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178929.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178935.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178938.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178941.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178942.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178944.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178945.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178946.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178947.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178948.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178949.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178951.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178954.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178955.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178956.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178958.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178960.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178962.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178963.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178964.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178967.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178968.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178972.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178974.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178975.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178980.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913\A0178982.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP914\A0179045.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP914\A0179048.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP914\A0179049.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP914\A0179050.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179052.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179053.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179054.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179055.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179056.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179057.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179058.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179060.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179061.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179062.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179063.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179064.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179066.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179067.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179068.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179069.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179070.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179071.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179072.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179073.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179074.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179075.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179076.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179078.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179079.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179080.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179081.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915\A0179082.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP916\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped C:\WINDOWS\Internet Logs\NEWDELL.ldb Object is locked skipped C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{31DF8357-8BBD-489A-9E26-C6AD90AE6DA7}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\DEFAULT Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SYSTEM Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\spool\PRINTERS\FP00001.SHD Object is locked skipped C:\WINDOWS\system32\spool\PRINTERS\FP00001.SPL Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_69c.dat Object is locked skipped C:\WINDOWS\Temp\ZLT01477.TMP Object is locked skipped C:\WINDOWS\Temp\ZLT0147e.TMP Object is locked skipped C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: [external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    [external image: Posted Image]
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
Express Scan found no viruses Complete Scan found 116 here is the list A0178889.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178893.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178895.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178896.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178898.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178899.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178900.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178901.EXE;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178902.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178903.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178904.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178905.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178906.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178907.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178908.EXE;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178909.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178910.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178911.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178912.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178913.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178914.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178915.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178916.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178917.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178918.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178919.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178929.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178935.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178938.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178941.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178942.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178944.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178945.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178946.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178947.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178948.EXE;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178949.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178951.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178954.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178955.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178956.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178958.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178960.EXE;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178962.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178963.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178964.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178967.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178968.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178972.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178974.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178975.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178980.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0178982.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP913;Trojan.MulDrop.9328;Deleted.; A0179045.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP914;Trojan.MulDrop.9328;Deleted.; A0179048.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP914;Trojan.MulDrop.9328;Deleted.; A0179049.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP914;Trojan.MulDrop.9328;Deleted.; A0179050.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP914;Trojan.MulDrop.9328;Deleted.; A0179052.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179053.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179054.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179055.EXE;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179056.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179057.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179058.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179060.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179061.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179062.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179063.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179064.EXE;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179066.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179067.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179068.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179069.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179070.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179071.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179072.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179073.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179074.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179075.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179076.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179078.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179079.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179080.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179081.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179082.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP915;Trojan.MulDrop.9328;Deleted.; A0179407.reg;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP916;Trojan.StartPage.1505;Deleted.; AdobeUpdater.exe.vir;C:\QooBox\Quarantine\C\Program Files\Common Files\Adobe\Updater5;Trojan.MulDrop.9328;Deleted.; ctfmon.exe.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.MulDrop.9328;Deleted.; CTSysVol.exe.vir;C:\QooBox\Quarantine\C\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer;Trojan.MulDrop.9328;Deleted.; DMXLauncher.exe.vir;C:\QooBox\Quarantine\C\Program Files\Dell\Media Experience;Trojan.MulDrop.9328;Deleted.; DSAgnt.exe.vir;C:\QooBox\Quarantine\C\Program Files\DellSupport;Trojan.MulDrop.9328;Deleted.; E_S4I2G1.EXE.vir;C:\QooBox\Quarantine\C\WINDOWS\system32\spool\drivers\w32x86\3;Trojan.MulDrop.9328;Deleted.; hkcmd.exe.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.MulDrop.9328;Deleted.; igfxpers.exe.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.MulDrop.9328;Deleted.; igfxtray.exe.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.MulDrop.9328;Deleted.; IntelMEM.exe.vir;C:\QooBox\Quarantine\C\Program Files\Intel\Modem Event Monitor;Trojan.MulDrop.9328;Deleted.; issch.exe.vir;C:\QooBox\Quarantine\C\Program Files\Common Files\InstallShield\UpdateService;Trojan.MulDrop.9328;Deleted.; ISUSPM .exe.vir;C:\QooBox\Quarantine\C\Program Files\COMMON~1\INSTAL~1\UPDATE~1;Trojan.MulDrop.9328;Deleted.; ISUSPM .exe.vir;C:\QooBox\Quarantine\C\Program Files\COMMON~1\INSTAL~1\UPDATE~1;Trojan.MulDrop.9328;Deleted.; ISUSPM.exe.vir;C:\QooBox\Quarantine\C\Program Files\COMMON~1\INSTAL~1\UPDATE~1;Trojan.MulDrop.9328;Deleted.; jusched.exe.vir;C:\QooBox\Quarantine\C\Program Files\Java\jre1.6.0_03\bin;Trojan.MulDrop.9328;Deleted.; mllmn.exe.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.MulDrop.9328;Deleted.; mm_tray.exe.vir;C:\QooBox\Quarantine\C\Program Files\MUSICMATCH\Musicmatch Jukebox;Trojan.MulDrop.9328;Deleted.; mmtask.exe.vir;C:\QooBox\Quarantine\C\Program Files\MUSICMATCH\Musicmatch Jukebox;Trojan.MulDrop.9328;Deleted.; msmsgs.exe.vir;C:\QooBox\Quarantine\C\Program Files\Messenger;Trojan.MulDrop.9328;Deleted.; PDVDServ.exe.vir;C:\QooBox\Quarantine\C\Program Files\CyberLink\PowerDVD;Trojan.MulDrop.9328;Deleted.; PSDrvCheck.exe.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.MulDrop.9328;Deleted.; RCX52.tmp.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.MulDrop.9328;Deleted.; Reader_sl.exe.vir;C:\QooBox\Quarantine\C\Program Files\Adobe\Reader 8.0\Reader;Trojan.MulDrop.9328;Deleted.; RealPlay.exe.vir;C:\QooBox\Quarantine\C\Program Files\Real\RealPlayer;Trojan.MulDrop.9328;Deleted.; RegUBP2b-Mark.reg;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2;Trojan.StartPage.1505;Deleted.; SDTrayApp.exe.vir;C:\QooBox\Quarantine\C\Program Files\Spyware Doctor;Trojan.MulDrop.9328;Deleted.; TeaTimer.exe.vir;C:\QooBox\Quarantine\C\Program Files\Spybot - Search & Destroy;Trojan.MulDrop.9328;Deleted.; tfswctrl.exe.vir;C:\QooBox\Quarantine\C\WINDOWS\system32\dla;Trojan.MulDrop.9328;Deleted.; UpdReg.EXE.vir;C:\QooBox\Quarantine\C\WINDOWS;Trojan.MulDrop.9328;Deleted.; USBTip.exe.vir;C:\QooBox\Quarantine\C\Program Files\Pinnacle\Shared Files\Programs\USBTip;Trojan.MulDrop.9328;Deleted.;
As this infection is changing daily, combofix is also.

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    • [external image: Posted Image]
  • If shown the disclaimer, Select "2"

Get the latest:

Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:17:24 AM, on 1/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\Spyware.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotwheelscollectors.com/default.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [PCLEUSBTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" -scheduler
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-1790839409-2520269449-3199803468-1008\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Nick')
O4 - HKUS\S-1-5-21-1790839409-2520269449-3199803468-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Nick')
O4 - HKUS\S-1-5-21-1790839409-2520269449-3199803468-1008\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" -scheduler (User 'Nick')
O4 - HKUS\S-1-5-21-1790839409-2520269449-3199803468-1008\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (User 'Nick')
O4 - HKUS\S-1-5-21-1790839409-2520269449-3199803468-1008\..\Run: [QdrModule11] "C:\Program Files\QdrModule\QdrModule11.exe" (User 'Nick')
O4 - HKUS\S-1-5-21-1790839409-2520269449-3199803468-1008\..\Run: [QdrPack11] "C:\Program Files\QdrPack\QdrPack11.exe" (User 'Nick')
O4 - S-1-5-21-1790839409-2520269449-3199803468-1008 Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE (User 'Nick')
O4 - S-1-5-21-1790839409-2520269449-3199803468-1008 User Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE (User 'Nick')
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4058/ftp…ver/Coupons.cab
O16 - DPF: {D2349304-8F9E-4A54-ACF6-0F6104B44209} (SketchCtl.Pic1) - http://auditor.cuyahogacounty.us/repi/sketch/Sketch.ocx
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 12120 bytes

ComboFix 07-12-31.4 - Mark 2008-01-02 11:00:22.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.127 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-12-02 to 2008-01-02 )))))))))))))))))))))))))))))))
.

2008-01-01 18:23 . 2008-01-01 18:23 d——– C:\Documents and Settings\Mark\DoctorWeb
2008-01-01 10:02 . 2008-01-01 10:02 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-01-01 10:02 . 2008-01-01 10:02 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-01 09:15 . 2007-12-31 21:26 406,016 –a—— C:\WINDOWS\system32\PSDrvCheck.exe
2008-01-01 09:15 . 2007-12-31 21:26 114,688 –a—— C:\WINDOWS\system32\igfxpers.exe
2008-01-01 09:15 . 2007-12-31 21:26 94,208 –a—— C:\WINDOWS\system32\igfxtray.exe
2008-01-01 09:15 . 2007-12-31 21:26 90,112 –a—— C:\WINDOWS\UpdReg.EXE
2008-01-01 09:15 . 2007-12-31 21:26 77,824 –a—— C:\WINDOWS\system32\hkcmd.exe
2007-12-31 21:51 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-12-31 16:02 . 2008-01-02 11:10 2,551,840 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-31 16:02 . 2008-01-01 20:46 29,420 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-31 15:57 . 2007-12-31 15:57 d——– C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-12-29 08:27 . 2008-01-01 20:48 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-28 17:13 . 2007-12-28 17:22 74,240 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-28 17:13 . 2007-12-28 17:22 56,832 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-28 17:13 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-28 17:13 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-28 17:12 . 2008-01-01 09:15 d——– C:\Program Files\Spyware Doctor
2007-12-28 17:12 . 2007-12-28 17:12 d——– C:\Documents and Settings\Mark\Application Data\PC Tools
2007-12-28 17:11 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-12-28 11:31 . 2007-12-28 11:31 d——– C:\Documents and Settings\Mark\Application Data\Apple Computer
2007-12-28 11:09 . 2007-12-28 11:09 d——– C:\Program Files\Apple Software Update
2007-12-28 11:07 . 2007-12-28 11:07 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-12-28 11:07 . 2007-10-31 14:09 30,464 –a—— C:\WINDOWS\system32\drivers\usbaapl.sys
2007-12-28 11:06 . 2007-12-28 11:06 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-12-27 11:08 . 2005-08-26 12:11 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-12-27 11:08 . 2005-08-26 12:24 d——– C:\Documents and Settings\Administrator\Application Data\Creative
2007-12-26 23:14 . 2007-12-26 23:13 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-12-26 23:13 . 2007-12-26 23:31 d——– C:\Documents and Settings\Mark\.housecall6.6
2007-12-26 22:49 . 2007-12-26 22:49 d——– C:\Program Files\Trend Micro
2007-12-26 13:10 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-12-26 13:10 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-26 13:10 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-26 13:10 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-26 13:10 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-26 13:10 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-26 13:09 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-12-26 13:09 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2007-12-25 09:58 . 2007-12-26 20:14 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-24 10:40 . 2007-12-28 11:29 d——– C:\Program Files\iTunes
2007-12-24 10:40 . 2007-12-24 10:40 d——– C:\Program Files\iPod
2007-12-24 10:30 . 2007-12-26 12:35 d——– C:\Program Files\Apple Software Update(2)
2007-12-24 10:27 . 2007-12-24 10:27 d——– C:\Program Files\Common Files\Apple
2007-12-18 20:48 . 2007-12-18 20:48 d——– C:\Program Files\Logitech
2007-12-18 20:48 . 2007-12-18 20:48 d——– C:\Program Files\Common Files\Logitech
2007-12-18 20:48 . 2005-04-12 19:21 45,504 –a—— C:\WINDOWS\system32\drivers\WmXlCore.sys
2007-12-18 20:48 . 2005-04-12 19:21 22,240 –a—— C:\WINDOWS\system32\drivers\WmFilter.sys
2007-12-18 20:48 . 2005-04-12 19:21 10,144 –a—— C:\WINDOWS\system32\drivers\WmBEnum.sys
2007-12-18 20:48 . 2005-04-12 19:21 5,600 –a—— C:\WINDOWS\system32\drivers\WmVirHid.sys
2007-12-15 22:27 . 2007-12-29 11:34 d——– C:\Program Files\Project64 1.6
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-09 20:59 . 2007-12-10 22:01 d——– C:\Program Files\Azureus
2007-12-09 20:59 . 2007-12-13 16:48 d——– C:\Documents and Settings\Nick\Application Data\Azureus
2007-12-09 20:53 . 2007-12-09 20:53 d——– C:\Downloads

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-01 14:15 ——— d—–w C:\Program Files\QuickTime
2008-01-01 14:15 ——— d—–w C:\Program Files\DellSupport
2008-01-01 02:27 15,360 —-a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-01-01 02:27 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
2007-12-30 21:07 ——— d—–w C:\Program Files\Quicken
2007-12-28 16:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-24 15:42 ——— d—–w C:\Documents and Settings\Nick\Application Data\Apple Computer
2007-12-21 23:58 11,031,348 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-12-21 23:08 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-10 02:45 ——— d—–w C:\Program Files\BitComet
2007-11-30 22:19 ——— d—–w C:\Program Files\IZArc
2007-11-29 00:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Smilebox
2007-11-18 14:05 ——— d—–w C:\Program Files\Java
2007-11-14 21:05 75,248 —-a-w C:\WINDOWS\zllsputility.exe
2007-11-14 21:05 1,086,952 —-a-w C:\WINDOWS\system32\zpeng24.dll
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-11 22:05 73,216 —-a-w C:\WINDOWS\ST6UNST.EXE
2007-11-11 22:04 19,659,826 —-a-w C:\WINDOWS\system32\lebronjames0607.scr
2007-11-03 20:13 ——— d—–w C:\Program Files\Fire International
2007-11-03 13:52 49,827 —-a-w C:\Uninstal.exe
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ——w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ——w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ——w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ——w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ——w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ——w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ——w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ——w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2002-07-26 21:02 153,088 —-a-w C:\Program Files\UNWISE.EXE
2007-09-27 02:35 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
—-a-w			79,224 2008-01-01 02:26:57  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
——w		   919,280 2007-12-31 20:29:19  C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe


((((((((((((((((((((((((((((( snapshot@2007-12-31_22.31.10.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-01 02:26:53 122,941 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
+ 2005-05-24 17:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2008-01-01 02:26:21 99,840 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2G1.EXE
+ 2008-01-02 01:47:43 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_6a0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2007-12-31 21:48 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-12-31 21:27 15360]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" [ ]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-12-31 21:27 460784]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-12-31 21:27 2321600]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-12-31 21:27 1460560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-12-31 21:25 132496]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2007-12-31 21:26 221184]
"CTSysVol"="C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2007-12-31 21:26 57344]
"P17Helper"="P17.dll" [2004-06-10 16:51 60928 C:\WINDOWS\system32\P17.dll]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2007-12-31 21:26 90112]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2007-12-31 21:26 131072]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2007-12-31 21:26 53248]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2007-12-31 21:26 26112]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [ ]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2007-12-31 21:26 86960]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2007-12-31 21:26 86016]
"EPSON Stylus CX5400"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.exe" [2007-12-31 21:26 99840]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2007-12-31 21:26 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2007-12-31 21:26 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2007-12-31 21:26 114688]
"PinnacleDriverCheck"="C:\WINDOWS\system32\\PSDrvCheck.exe" [2007-12-31 21:26 406016]
"PCLEUSBTip"="C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe" [2007-12-31 21:26 196608]
"USB2Check"="C:\WINDOWS\system32\PCLECoInst.dll" [2005-12-21 09:14 73728]
"USBToolTip"="C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [2007-12-31 21:26 196608]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-12-31 21:26 32768]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2007-12-31 21:26 122941]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-12-31 21:26 39792]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" [ ]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-12-31 21:27 1065800]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]

C:\Documents and Settings\Nick\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2003-09-25 09:47:12]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Dataviz Messenger.lnk - C:\WINDOWS\DvzCommon\DvzMsgr.exe [2003-07-01 20:16:46]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 11:59:36]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - C:\Program Files\WiFiConnector\NintendoWFCReg.exe [2006-12-25 22:11:14]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""


.
Contents of the 'Scheduled Tasks' folder
"2007-12-29 17:23:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-02 02:55:22 C:\WINDOWS\Tasks\User_Feed_Synchronization-{50D0D4BC-426E-44B2-9BFA-DEE6413827B3}.job"
- C:\WINDOWS\system32\msfeedssync.exe
"2008-01-02 06:36:33 C:\WINDOWS\Tasks\User_Feed_Synchronization-{92AE00CF-95FA-45D4-8547-820AEBE39993}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-02 11:10:36
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\ArcSoft\Software Suite\PhotoImpression 5\share\pihook.dll
.
Completion time: 2008-01-02 11:16:03
C:\qoobox\ComboFix-quarantined-files.txt 2008-01-02 16:15:51
C:\qoobox\ComboFix2.txt 2008-01-01 14:30:04
C:\qoobox\ComboFix3.txt 2008-01-01 03:32:14
C:\qoobox\ComboFix4.txt 2007-12-31 22:08:04
C:\qoobox\ComboFix5.txt 2007-12-31 18:59:57
.
2007-12-27 12:33:26 — E O F —
Your Avast4 anti-virus and Zonealarm firewall are infected.
You'll need to unistall and re-install them.


Please do not delete anything unless instructed to.


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
Avast4
ZoneAlarm


Avast4
http://www.avast.com/eng/download-avast-home.html

Zonealarm
http://filehippo.com/download_zonealarm_free/

Download and install both.

After the above:


  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI