This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help - Computer out of control with viruses - adware

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Not sure what I did, but the last few weeks and my computer is out of control. I've been known to be very safe with what i download and having spyware and norton runing with updated def files all the time. This time I don't know what I did….the only thing I can think of was the few episodes of niptuck i downloaded using ares…but who knows. Using norton, heres a list of what it shows for viruses.: (sorry about the lengh) see attached file as you can see, there's a lot in the history..this is all from this past month..well 99% of it. The issues i'm facing right now: i ran a vundofix file for a adware and it said it fixed the adware that kept popping up over and over, but seems to have caused new problems - when my computer boots up, it says im missing a few files.ssts.exe and another one .dll file - my shortcuts are being re-routed to a tmp file so it cant find the application to run. - computer runs very slow - computers trying to install norton even though its on the computer already - various popups - and virus file after virus file being found..same one over and over by norton can you HELP Paul

Attachments:

thanks…I did what it said and installed the hijackthis program, here is the log below.

Logfile of HijackThis v1.99.1
Scan saved at 9:48:19 PM, on 12/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Symantec AntiVirus\vptray.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\Program Files\AIM6\aim6 .exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\sstst.exe
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\system32\fast.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P24 "EPSON Stylus Photo RX500" /O14 "IP_LKD160A2_P1" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500 (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P33 "EPSON Stylus Photo RX500 (Copy 1)" /O6 "USB002" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PrintServer Diagnostic] C:\Program Files\Print Server\PTP\PSDiagnostic.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu72.exe 61A847B5BBF72815308B2B27128065E9C084320161C4661227A755E9C2933154389A
O4 - HKLM\..\Run: [c0463754] rundll32.exe "C:\WINDOWS\system32\pwiobbot.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [QdrPack11] "C:\Program Files\QdrPack\QdrPack11.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe" -quiet
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch .exe"
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Betus Poker - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\BETUSP~1\client.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.net\PartyPokerNet\RunPF.exe
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.net\PartyPokerNet\RunPF.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {528C14CD-CF9E-489C-A365-5999F17B69B9} (LightSurfUploadCtl Class) - http://pictures.sprintpcs.com/activex/Ligh…loadControl.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1124668838993
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.dotphoto.com/ImageUploader4.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.dotphoto.com/DPImageUploader.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} - http://static.zangocash.com/cab/Seekmo/ie/…5d3c47945c52d3d
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.dotphoto.com/XUpload.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InteractiveLogon - Unknown owner - C:\WINDOWS\system32\Fast.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hi Paul,

Thanks, yes, you have several infections going on here. This will likely take several steps so please be patient as we go here…


Please download SDFix and save it to your Desktop.

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • Open the SDFix folder and double click on RunThis.bat to start the script.
  • Type Y and press Enter to begin the script.
  • It will start cleaning your PC and then prompt you to press any key to Reboot.
  • Press any key to restart the PC.
  • Your system will take longer than normal to restart as the fixtool will be removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished.
  • Press any key to end the script and to load your desktop icons.
  • A text file should automatically open, so please copy the contents and post them here.

——————————————————————

Please download ComboFix by sUBs from HERE or HERE
  • You must download it to and run it from your Desktop
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
  • Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
thanks…a few things before I reply with the info in each of the txt files

Now when my computer reboots, i get a error before the user logon screen saying:

Defwatch.exe application error exception unknown software exception (0xc06d007e) occured in the applicaiton at location 0x7c812a5b.

after i logon to my user name, i receive a error saying:

error loading c:\windows\system32\pwiobbot.dll


hope you can help with those issues too.

here's the log file for sdfix:


SDFix: Version 1.121

Run by [removed] on Mon 12/31/2007 at 12:45 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\mrofinu72.exe.tmp - Deleted




Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1333.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-31 12:55:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SPBBCDrv\Parameters]
"Configuration"="C:\Program Files\Common Files\Symantec Shared\SPBBC\2007-12-29-592a.kc"

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\InterVideo\\DVD6\\WinDVD.exe"="C:\\Program Files\\InterVideo\\DVD6\\WinDVD.exe:*:Enabled:WinDVD"
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE:*:Disabled:SAgent4"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Documents and Settings\\USER\\Desktop\\Fortec\\keymaster3.0.exe"="C:\\Documents and Settings\\USER\\Desktop\\Fortec\\keymaster3.0.exe:*:Enabled:keymaster3.0"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\Motorola\\Software Update\\msu.exe"="C:\\Program Files\\Motorola\\Software Update\\msu.exe:*:Enabled:msu"
"C:\\Program Files\\Ares\\Ares.exe"="C:\\Program Files\\Ares\\Ares.exe:*:Enabled:Ares p2p for windows"
"C:\\Program Files\\TurboTax\\Deluxe 2006\\32bit\\ttax.exe"="C:\\Program Files\\TurboTax\\Deluxe 2006\\32bit\\ttax.exe:LocalSubNet:Enabled:TurboTax"
"C:\\Program Files\\TurboTax\\Deluxe 2006\\32bit\\updatemgr.exe"="C:\\Program Files\\TurboTax\\Deluxe 2006\\32bit\\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager"
"C:\\Program Files\\MSN Messenger\\msnmsgr .exe"="C:\\Program Files\\MSN Messenger\\msnmsgr .exe:*:Enabled:Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YAHOOM~1 .EXE"="C:\\Program Files\\Yahoo!\\Messenger\\YAHOOM~1 .EXE:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger .exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger .exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger .exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger .exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YAHOOM~1 .EXE"="C:\\Program Files\\Yahoo!\\Messenger\\YAHOOM~1 .EXE:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YAHOOM~1 .EXE"="C:\\Program Files\\Yahoo!\\Messenger\\YAHOOM~1 .EXE:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YAHOOM~1 .EXE"="C:\\Program Files\\Yahoo!\\Messenger\\YAHOOM~1 .EXE:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger .exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger .exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger .exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger .exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"="C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe:*:Enabled:MySpaceIM"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Remaining Files:
—————

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Wed 13 Oct 2004 1,694,208 ..SH. — "C:\Program Files\Messenger\msmsgs.exe"
Tue 4 Oct 2005 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 6 Nov 2006 72,704 ..SHR — "C:\Program Files\DssEvolution.com\KeyRipper\Setup.exe"
Tue 10 Apr 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Thu 12 Apr 2007 8 A..H. — "C:\Documents and Settings\USER\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Thu 12 Apr 2007 8 A..H. — "C:\Documents and Settings\USER\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Thu 12 Apr 2007 8 A..H. — "C:\Documents and Settings\USER\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Thu 12 Apr 2007 8 A..H. — "C:\Documents and Settings\USER\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"

Finished!


Here's the log file from combofix:


ComboFix 07-12-31.4 - USER 2007-12-31 13:05:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.592 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Common Files\ssembl~1
C:\Program Files\Common Files\ssembl~1\?ssembly\
C:\Program Files\QdrDrive
C:\Program Files\QdrModule
C:\Program Files\QdrModule\dic.gz
C:\Program Files\QdrModule\kwd.gz
C:\Program Files\QdrModule\QdrModule11 .exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\clrsngxj.dll
C:\WINDOWS\system32\cnmgthyq.dll
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\fndeyeqi.dll
C:\WINDOWS\system32\hlyvkacq.dll
C:\WINDOWS\system32\itbqmpdc.dll
C:\WINDOWS\system32\lixhgycp.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\oprxiksk.dll
C:\WINDOWS\system32\rsdubgqn.dll
C:\WINDOWS\system32\srtelktu.dll
C:\WINDOWS\system32\sstst.dll
C:\WINDOWS\system32\tstss.ini
C:\WINDOWS\system32\tstss.ini2
C:\WINDOWS\system32\vjeqhjvl.dll

.
((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-31 )))))))))))))))))))))))))))))))
.

2007-12-31 13:03 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-12-31 12:43 . 2007-12-31 12:44 d——– C:\WINDOWS\ERUNT
2007-12-29 22:20 . 2007-12-29 22:20 256 –a—— C:\Documents and Settings\USER\pool.bin
2007-12-28 13:40 . 2007-12-29 13:41 1,031,319 –ahs—- C:\WINDOWS\system32\jreqlgnv.ini
2007-12-28 13:34 . 2007-12-28 13:35 1,031,259 –ahs—- C:\WINDOWS\system32\vtqncsgv.ini
2007-12-27 13:40 . 2007-12-27 13:41 1,031,199 –ahs—- C:\WINDOWS\system32\sokwsqjn.ini
2007-12-27 13:38 . 2007-12-27 13:38 1,031,139 –ahs—- C:\WINDOWS\system32\riampacx.ini
2007-12-26 19:33 . 2007-12-26 19:33 d——– C:\Documents and Settings\USER\Application Data\Lavasoft
2007-12-26 19:32 . 2007-12-26 19:32 d——– C:\Program Files\Lavasoft
2007-12-26 19:27 . 2007-12-26 19:27 d——– C:\Program Files\Webroot
2007-12-26 19:27 . 2003-10-15 23:52 348,160 –a—— C:\WINDOWS\unSpySweeper.exe
2007-12-26 03:00 . 2007-12-26 03:00 d——– C:\Program Files\MSXML 6.0
2007-12-25 14:26 . 2007-12-30 00:23 d——– C:\VundoFix Backups
2007-12-25 06:31 . 2007-12-25 09:53 1,023,120 –ahs—- C:\WINDOWS\system32\tobboiwp.ini
2007-12-24 17:38 . 2007-12-24 17:38 d——– C:\Documents and Settings\USER\Application Data\Blackberry Desktop
2007-12-24 17:02 . 2007-12-29 22:36 256 –a—— C:\WINDOWS\system32\pool.bin
2007-12-24 17:01 . 2007-12-24 17:01 d——– C:\Documents and Settings\USER\Application Data\Research In Motion
2007-12-24 16:39 . 2007-12-24 16:39 d——– C:\Program Files\Common Files\Sonic Shared
2007-12-24 16:29 . 2007-01-18 10:24 26,496 -ra—— C:\WINDOWS\system32\drivers\RimSerial.sys
2007-12-24 16:27 . 2007-12-24 16:27 d——– C:\Program Files\Common Files\Research In Motion
2007-12-24 16:26 . 2007-12-24 16:26 d——– C:\Program Files\Research In Motion
2007-12-24 00:28 . 2007-12-24 00:28 d——– C:\Documents and Settings\Guest\Application Data\Roxio
2007-12-23 18:32 . 2007-12-24 17:18 1,014,194 –ahs—- C:\WINDOWS\system32\rmbmcvnl.ini
2007-12-23 11:41 . 2007-12-31 12:42 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2007-12-22 12:14 . 2007-12-25 09:51 118,784 –a—— C:\WINDOWS\system32\igfxpers .exe
2007-12-22 12:14 . 2007-12-25 09:51 94,208 –a—— C:\WINDOWS\system32\igfxtray .exe
2007-12-22 12:14 . 2007-12-25 09:51 77,824 –a—— C:\WINDOWS\system32\hkcmd .exe
2007-12-22 12:13 . 2007-12-26 20:35 221,184 –a—— C:\WINDOWS\system32\LVCOMSX .EXE
2007-12-22 12:13 . 2007-12-25 09:50 155,648 –a—— C:\WINDOWS\system32\NeroCheck .exe
2007-12-22 12:12 . 2007-12-25 09:50 45,632 –a—— C:\WINDOWS\system32\taskswitch .exe
2007-12-22 12:04 . 2007-12-25 09:50 49,216 –a—— C:\WINDOWS\system32\Fast .exe
2007-12-13 22:16 . 2007-12-22 18:03 d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-12-02 13:04 . 2007-12-27 17:20 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-02 13:04 . 2007-12-02 13:04 1,409 –a—— C:\WINDOWS\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-31 18:54 ——— d—–w C:\Program Files\Symantec AntiVirus
2007-12-31 18:54 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-30 05:29 ——— d—–w C:\Program Files\AIM6
2007-12-30 05:28 ——— d—–w C:\Program Files\Common Files\AOL
2007-12-30 05:28 ——— d—–w C:\Program Files\AIM
2007-12-30 05:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-12-30 05:10 ——— d—–w C:\Program Files\MSN Messenger
2007-12-30 04:23 ——— d—–w C:\Program Files\Windows Defender
2007-12-30 04:23 ——— d—–w C:\Program Files\QuickTime
2007-12-30 04:23 ——— d—–w C:\Program Files\DellSupport
2007-12-24 22:50 ——— d—–w C:\Program Files\Roxio
2007-12-24 22:41 ——— d—–w C:\Program Files\Common Files\Roxio Shared
2007-12-24 06:01 ——— d—–w C:\Documents and Settings\Guest\Application Data\Yahoo!
2007-12-24 05:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-12-23 18:52 ——— d–h–r C:\Documents and Settings\USER\Application Data\yahoo!
2007-12-23 00:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\yahoo!
2007-12-14 04:12 ——— d—–w C:\Program Files\Yahoo!
2007-12-13 04:40 ——— d—–w C:\Program Files\FriendBlasterPro
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
.
—-a-w			57,344 2007-12-27 02:36:32  C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy .exe
—-a-w			50,528 2007-12-27 02:37:32  C:\Program Files\AIM6\aim6 .exe
—-a-w			52,840 2007-12-27 02:36:58  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   460,784 2007-12-27 02:37:20  C:\Program Files\DellSupport\DSAgnt .exe
—-a-w		   479,232 2007-12-27 02:36:00  C:\Program Files\Google\Gmail Notifier\gnotify .exe
—-a-w		   132,496 2007-12-27 02:35:46  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		   217,088 2007-12-27 02:35:57  C:\Program Files\Logitech\Video\LogiTray .exe
—-a-w		 5,674,352 2007-12-29 17:14:00  C:\Program Files\MSN Messenger\msnmsgr .exe
—-a-w		 8,720,384 2007-12-27 02:38:32  C:\Program Files\MySpace\IM\MySpaceIM .exe
—-a-w		   266,240 2007-12-27 02:36:42  C:\Program Files\Print Server\PTP\PSDiagnostic .exe
—-a-w		   282,624 2007-12-27 02:36:59  C:\Program Files\QuickTime\qttask			.exe
—-a-w		   282,624 2007-12-30 06:16:58  C:\Program Files\QuickTime\qttask		  .exe
—-a-w		   282,624 2007-12-30 06:16:58  C:\Program Files\QuickTime\qttask		 .exe
—-a-w		   282,624 2007-12-30 06:16:59  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   282,624 2007-12-30 06:17:00  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   282,624 2007-12-30 06:17:01  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   282,624 2007-12-30 06:17:01  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   282,624 2007-12-30 06:17:02  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   282,624 2007-12-30 06:17:02  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   282,624 2007-12-30 06:17:03  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   282,624 2007-12-30 06:17:03  C:\Program Files\QuickTime\qttask .exe
—-a-w		 1,179,648 2007-12-27 02:35:42  C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc .exe
—-a-w		   125,632 2007-12-27 02:36:58  C:\Program Files\Symantec AntiVirus\VPTray .exe
—-a-w		   866,584 2007-12-27 02:36:50  C:\Program Files\Windows Defender\MSASCui .exe
—-a-w		 4,670,704 2007-12-27 02:38:51  C:\Program Files\Yahoo!\Messenger\YahooMessenger	.exe
—-a-w		 4,670,704 2007-12-30 05:37:45  C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
—-a-w		 4,670,704 2007-12-30 05:37:38  C:\Program Files\Yahoo!\Messenger\YAHOOM~1	  .EXE
—-a-w		 4,670,704 2007-12-30 05:37:30  C:\Program Files\Yahoo!\Messenger\YAHOOM~1	 .EXE
—-a-w		 4,670,704 2007-12-30 05:37:13  C:\Program Files\Yahoo!\Messenger\YAHOOM~1	.EXE
—-a-w		 4,670,704 2007-12-30 05:37:07  C:\Program Files\Yahoo!\Messenger\YAHOOM~1   .EXE
—-a-w		 4,670,704 2007-12-30 05:37:02  C:\Program Files\Yahoo!\Messenger\YAHOOM~1  .EXE
—-a-w		 4,670,704 2007-12-30 05:36:58  C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
—-a-w			15,360 2007-12-31 18:42:54  C:\WINDOWS\system32\ctfmon .exe
—-a-w			49,216 2007-12-25 15:50:17  C:\WINDOWS\system32\Fast .exe
—-a-w			77,824 2007-12-25 15:51:26  C:\WINDOWS\system32\hkcmd .exe
—-a-w		   118,784 2007-12-25 15:51:40  C:\WINDOWS\system32\igfxpers .exe
—-a-w			94,208 2007-12-25 15:51:18  C:\WINDOWS\system32\igfxtray .exe
—-a-w		   221,184 2007-12-27 02:35:54  C:\WINDOWS\system32\LVCOMSX .EXE
—-a-w		   155,648 2007-12-25 15:50:51  C:\WINDOWS\system32\NeroCheck .exe
—-a-w			45,632 2007-12-25 15:50:49  C:\WINDOWS\system32\taskswitch .exe
—-a-w			99,840 2007-12-27 02:36:27  C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2K1 .EXE


– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [ ]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [ ]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [ ]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]
"QdrPack11"="C:\Program Files\QdrPack\QdrPack11.exe" [ ]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe" [ ]
"AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch .exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoxioDragToDisc"="C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" [ ]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [ ]
"FastUser"="C:\WINDOWS\system32\fast.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [ ]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [ ]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [ ]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [ ]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [ ]
"EPSON Stylus Photo RX500"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.exe" [ ]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-06-08 11:31 29696 C:\WINDOWS\KHALMNPR.Exe]
"EPSON Stylus Photo RX500 (Copy 1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.exe" [ ]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [ ]
"PrintServer Diagnostic"="C:\Program Files\Print Server\PTP\PSDiagnostic.exe" [ ]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [ ]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [ ]
"vptray"="C:\PROGRA~1\SYMANT~2\VPTray.exe" [ ]
"c0463754"="C:\WINDOWS\system32\pwiobbot.dll" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 12:45 36040]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\KEM.exe [2005-10-10 22:41:54]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-09-14 10:02:45]

R1 UDFReadr;UDFReadr;C:\WINDOWS\system32\drivers\UDFReadr.sys [2004-02-26 05:58]
R3 ADM851X;ADM851X USB To Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\ADM851X.SYS [2004-10-27 15:05]
R3 LUsbKbd;Logitech SetPoint USB Keyboard Filter;C:\WINDOWS\system32\Drivers\LUsbKbd.Sys [2004-06-08 11:36]
S3 flash;flash;C:\WINDOWS\system32\drivers\flash.sys [2003-08-29 17:47]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-31 19:16:41 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-31 13:16:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\Program Files\ArcSoft\Software Suite\PhotoImpression 5\share\pihook.dll
-> C:\Program Files\Logitech\SetPoint\lgscroll.dll
.
Completion time: 2007-12-31 13:19:18 - machine was rebooted
C:\qoobox\ComboFix-quarantined-files.txt 2007-12-31 19:19:13
.
2007-12-27 23:55:16 — E O F —
Unfortunately you have way more troubles here than just those error messages, those are only a small part of your problems.

You may have a new Vundo variant that infects .exe files. All of those .exe files shown in the code box are possibly infected.

I would like to get a Kaspersky scan here and get some other experts to look in here. Do you have your XP disc? The best option here may be to back up any data files you have then re-install Windows. This is not good. Let's get the Kaspersky scan and go from there.

Using Internet Explorer, click on Kaspersky Online Scanner * Click 'Accept' in the window that pops up.
* You will be prompted to install an ActiveX component from Kaspersky, Click on the information bar and select Install ActiveX Control if so. This may happen more than once. That is OK. You also may get a warning from your Windows Firewall. You can tell it to unblock.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save Report As…' button:
* Make sure it says Save as a text file - change it if not
* Save the file to your desktop.
Please post the Kaspersky report and a new HijackThis log.
——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Monday, December 31, 2007 5:11:24 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 31/12/2007 Kaspersky Anti-Virus database records: 500861 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - Folders: C:\ Scan Statistics: Total number of scanned objects: 81989 Number of viruses found: 7 Number of infected objects: 19 Number of suspicious objects: 0 Duration of the scan process: 01:22:46 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12072006-001129.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\USER\Application Data\acccore\nss\cert8.db Object is locked skipped C:\Documents and Settings\USER\Application Data\acccore\nss\key3.db Object is locked skipped C:\Documents and Settings\USER\Application Data\Sun\Java\Deployment\cache\6.0\6\2b548146-630f5738/NewURLClassLoader.class Infected: Exploit.Java.ByteVerify skipped C:\Documents and Settings\USER\Application Data\Sun\Java\Deployment\cache\6.0\6\2b548146-630f5738 ZIP: infected - 1 skipped C:\Documents and Settings\USER\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-47723671-782ce483.zip/NewURLClassLoader.class Infected: Exploit.Java.ByteVerify skipped C:\Documents and Settings\USER\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-47723671-782ce483.zip ZIP: infected - 1 skipped C:\Documents and Settings\USER\Cookies\index.dat Object is locked skipped C:\Documents and Settings\USER\Local Settings\Application Data\AOL OCP\AIM\Storage\All Users\localStorage\common.cls Object is locked skipped C:\Documents and Settings\USER\Local Settings\Application Data\AOL OCP\AIM\Storage\data\paulp73\localStorage\common.cls Object is locked skipped C:\Documents and Settings\USER\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\USER\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\USER\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\USER\Local Settings\History\History.IE5\MSHist012007123120080101\index.dat Object is locked skipped C:\Documents and Settings\USER\Local Settings\Temp\Perflib_Perfdata_89c.dat Object is locked skipped C:\Documents and Settings\USER\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\USER\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\USER\NTUSER.DAT Object is locked skipped C:\Documents and Settings\USER\ntuser.dat.LOG Object is locked skipped C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped C:\Program Files\Symantec AntiVirus\SAVRT\0008NAV~.TMP Object is locked skipped C:\Program Files\Symantec AntiVirus\SAVRT\0202NAV~.TMP Object is locked skipped C:\Program Files\Yahoo!\Messenger\logs\billing_USER.log Object is locked skipped C:\Program Files\Yahoo!\Messenger\logs\client_USER.log Object is locked skipped C:\Program Files\Yahoo!\Messenger\logs\network_USER.log Object is locked skipped C:\SDFix\backups\backups.zip/backups/mrofinu72.exe.tmp Infected: Trojan-Downloader.Win32.Agent.gwh skipped C:\SDFix\backups\backups.zip ZIP: infected - 1 skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{1F4EA0E7-E44E-4DC1-BDD7-B7A00ACFD4BA}\RP1000\A0112830.exe Infected: Trojan-Downloader.Win32.Agent.gwh skipped C:\System Volume Information\_restore{1F4EA0E7-E44E-4DC1-BDD7-B7A00ACFD4BA}\RP1001\A0112968.exe Infected: Trojan-Downloader.Win32.Agent.gwh skipped C:\System Volume Information\_restore{1F4EA0E7-E44E-4DC1-BDD7-B7A00ACFD4BA}\RP1005\A0113516.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.clz skipped C:\System Volume Information\_restore{1F4EA0E7-E44E-4DC1-BDD7-B7A00ACFD4BA}\RP1012\change.log Object is locked skipped C:\System Volume Information\_restore{1F4EA0E7-E44E-4DC1-BDD7-B7A00ACFD4BA}\RP973\A0110287.exe Infected: not-a-virus:AdWare.Win32.Agent.vv skipped C:\System Volume Information\_restore{1F4EA0E7-E44E-4DC1-BDD7-B7A00ACFD4BA}\RP994\A0111158.exe Infected: Trojan-Downloader.Win32.PurityScan.fe skipped C:\System Volume Information\_restore{1F4EA0E7-E44E-4DC1-BDD7-B7A00ACFD4BA}\RP994\A0111159.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped C:\System Volume Information\_restore{1F4EA0E7-E44E-4DC1-BDD7-B7A00ACFD4BA}\RP995\A0111192.exe Infected: Trojan-Downloader.Win32.Osel.bx skipped C:\System Volume Information\_restore{1F4EA0E7-E44E-4DC1-BDD7-B7A00ACFD4BA}\RP995\A0111236.exe Infected: Trojan-Downloader.Win32.Agent.gwh skipped C:\System Volume Information\_restore{1F4EA0E7-E44E-4DC1-BDD7-B7A00ACFD4BA}\RP995\A0111350.exe Infected: not-a-virus:AdWare.Win32.Agent.vv skipped C:\System Volume Information\_restore{1F4EA0E7-E44E-4DC1-BDD7-B7A00ACFD4BA}\RP996\A0112588.exe Infected: Trojan-Downloader.Win32.Agent.gwh skipped C:\System Volume Information\_restore{1F4EA0E7-E44E-4DC1-BDD7-B7A00ACFD4BA}\RP997\A0112695.exe Infected: Trojan-Downloader.Win32.Agent.gwh skipped C:\VundoFix Backups\mrofinu72.exe.bad Infected: Trojan-Downloader.Win32.Agent.gwh skipped C:\VundoFix Backups\yayyvts.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.clz skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{94D8E18D-E935-4DB1-A276-A05C69197C8B}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
Hi and sorry for the little delay in getting back to you here. Well it's not as bad as I thought it would be. The infection is bad but combofix has been updated to deal with the worst of it. There are still things to be dealt with though and I need to do a little more research. Do me a favor and post a new Hijackthis log. Also, check out some or all of the programs that were affected by the file infecter. These are from the code box in the combofix report. Just make sure they work (or if they don't we'll have to deal with that). Adobe Photoshop Starter Edition AIM MySpace IM Roxio\Easy Media Creator 7 Your Norton Antivirus Windows Defender Yahoo Messenger
here's a few programs that are not working:
windows defender
gmail notifier
various aspects of roxio like drag and drop, but the main program opens
i reloaded yahoo and aim and they work fine now
computer continues to reload norton and roxio even though its on my computer, it ask for the load disk which i dont have anymore
gmial notfier is not working

thats all ive seen so far..here's the new hijack log

Logfile of HijackThis v1.99.1
Scan saved at 12:51:06 PM, on 1/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Symantec AntiVirus\vptray.exe
C:\Program Files\AIM6\aim6 .exe
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\system32\fast.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P24 "EPSON Stylus Photo RX500" /O14 "IP_LKD160A2_P1" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500 (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P33 "EPSON Stylus Photo RX500 (Copy 1)" /O6 "USB002" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PrintServer Diagnostic] C:\Program Files\Print Server\PTP\PSDiagnostic.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [c0463754] rundll32.exe "C:\WINDOWS\system32\pwiobbot.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [QdrPack11] "C:\Program Files\QdrPack\QdrPack11.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch .exe"
O4 - HKCU\..\RunOnce: [ypagerps] cmd.exe /C del "C:\PROGRA~1\Yahoo!\MESSEN~1\ypagerps.dll"
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Betus Poker - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\BETUSP~1\client.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.net\PartyPokerNet\RunPF.exe
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.net\PartyPokerNet\RunPF.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {528C14CD-CF9E-489C-A365-5999F17B69B9} (LightSurfUploadCtl Class) - http://pictures.sprintpcs.com/activex/Ligh…loadControl.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1124668838993
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.dotphoto.com/ImageUploader4.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.dotphoto.com/DPImageUploader.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} - http://static.zangocash.com/cab/Seekmo/ie/…5d3c47945c52d3d
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.dotphoto.com/XUpload.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InteractiveLogon - Unknown owner - C:\WINDOWS\system32\Fast.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hi Paul,

Well, this is going to be tricky. You have a couple of issues. One as you know some of your programs are not working because of the file infecter. And…you are still infected. This thing is nasty and if we don't get it all when you reboot again it just regenerates, as we've seen with those QdrPackxx.exe files. We should be able to get at least most of your programs back but we still need to deal with the infection first. Can you do me a favor, please don't reboot the computer unless I specify, or one of the tools like combofix reboots or asks for a reboot. Other than that leave the machine on if possible till I give the all clear.

Let's go at this again.

I'll give all the instructions over. Please remove the current versions of SDFix and combofix (and all associated files and folders) and download fresh ones, especially combofix as the developer is updating it constantly to deal with this new infection.

These instructions should look familiar…again, please avoid rebooting after running combofix.

Please download SDFix and save it to your Desktop.

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • Open the SDFix folder and double click on RunThis.bat to start the script.
  • Type Y and press Enter to begin the script.
  • It will start cleaning your PC and then prompt you to press any key to Reboot.
  • Press any key to restart the PC.
  • Your system will take longer than normal to restart as the fixtool will be removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished.
  • Press any key to end the script and to load your desktop icons.
  • A text file should automatically open, so please copy the contents and post them here.

——————————-

Please download ComboFix by sUBs from HERE or HERE
  • You must download it to and run it from your Desktop
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
  • Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
Yes, as I had said it's OK if needed for the tools. I am new to this infection, as most of the helpers are in these forums, and it may be overkill but I'd just like to make sure it doesn't respawn after running combofix. So after that just leave it.
sdfix log



SDFix: Version 1.121

Run by [removed] on Tue 01/01/2008 at 02:53 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

No Trojan Files Found





Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1333.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-01 15:00:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

Remaining Files:
—————


Files with Hidden Attributes:

Wed 13 Oct 2004 1,694,208 ..SH. — "C:\Program Files\Messenger\msmsgs.exe"
Tue 4 Oct 2005 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 6 Nov 2006 72,704 ..SHR — "C:\Program Files\DssEvolution.com\KeyRipper\Setup.exe"
Tue 10 Apr 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Mon 16 Apr 2007 8 A..H. — "C:\Documents and Settings\Guest\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Thu 12 Apr 2007 8 A..H. — "C:\Documents and Settings\USER\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Thu 12 Apr 2007 8 A..H. — "C:\Documents and Settings\USER\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Thu 12 Apr 2007 8 A..H. — "C:\Documents and Settings\USER\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Thu 12 Apr 2007 8 A..H. — "C:\Documents and Settings\USER\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"

Finished!



combofix log

ComboFix 07-12-31.4 - USER 2008-01-01 15:16:41.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.599 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-12-01 to 2008-01-01 )))))))))))))))))))))))))))))))
.

2007-12-31 15:37 . 2007-12-31 15:37 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-12-31 15:37 . 2007-12-31 15:37 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-31 13:03 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-12-31 12:43 . 2007-12-31 12:44 d——– C:\WINDOWS\ERUNT
2007-12-29 22:20 . 2007-12-29 22:20 256 –a—— C:\Documents and Settings\USER\pool.bin
2007-12-28 13:40 . 2007-12-29 13:41 1,031,319 –ahs—- C:\WINDOWS\system32\jreqlgnv.ini
2007-12-28 13:34 . 2007-12-28 13:35 1,031,259 –ahs—- C:\WINDOWS\system32\vtqncsgv.ini
2007-12-27 13:40 . 2007-12-27 13:41 1,031,199 –ahs—- C:\WINDOWS\system32\sokwsqjn.ini
2007-12-27 13:38 . 2007-12-27 13:38 1,031,139 –ahs—- C:\WINDOWS\system32\riampacx.ini
2007-12-26 19:33 . 2007-12-26 19:33 d——– C:\Documents and Settings\USER\Application Data\Lavasoft
2007-12-26 19:32 . 2007-12-26 19:32 d——– C:\Program Files\Lavasoft
2007-12-26 19:27 . 2007-12-26 19:27 d——– C:\Program Files\Webroot
2007-12-26 19:27 . 2003-10-15 23:52 348,160 –a—— C:\WINDOWS\unSpySweeper.exe
2007-12-26 03:00 . 2007-12-26 03:00 d——– C:\Program Files\MSXML 6.0
2007-12-25 14:26 . 2007-12-30 00:23 d——– C:\VundoFix Backups
2007-12-25 06:31 . 2007-12-25 09:53 1,023,120 –ahs—- C:\WINDOWS\system32\tobboiwp.ini
2007-12-24 17:38 . 2007-12-24 17:38 d——– C:\Documents and Settings\USER\Application Data\Blackberry Desktop
2007-12-24 17:02 . 2007-12-29 22:36 256 –a—— C:\WINDOWS\system32\pool.bin
2007-12-24 17:01 . 2007-12-24 17:01 d——– C:\Documents and Settings\USER\Application Data\Research In Motion
2007-12-24 16:39 . 2007-12-24 16:39 d——– C:\Program Files\Common Files\Sonic Shared
2007-12-24 16:29 . 2007-01-18 10:24 26,496 -ra—— C:\WINDOWS\system32\drivers\RimSerial.sys
2007-12-24 16:27 . 2007-12-24 16:27 d——– C:\Program Files\Common Files\Research In Motion
2007-12-24 16:26 . 2007-12-24 16:26 d——– C:\Program Files\Research In Motion
2007-12-24 00:28 . 2007-12-24 00:28 d——– C:\Documents and Settings\Guest\Application Data\Roxio
2007-12-23 18:32 . 2007-12-24 17:18 1,014,194 –ahs—- C:\WINDOWS\system32\rmbmcvnl.ini
2007-12-23 11:41 . 2007-12-31 12:42 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2007-12-22 12:14 . 2007-12-25 09:51 118,784 –a—— C:\WINDOWS\system32\igfxpers .exe
2007-12-22 12:14 . 2007-12-25 09:51 94,208 –a—— C:\WINDOWS\system32\igfxtray .exe
2007-12-22 12:14 . 2007-12-25 09:51 77,824 –a—— C:\WINDOWS\system32\hkcmd .exe
2007-12-22 12:13 . 2007-12-26 20:35 221,184 –a—— C:\WINDOWS\system32\LVCOMSX .EXE
2007-12-22 12:13 . 2007-12-25 09:50 155,648 –a—— C:\WINDOWS\system32\NeroCheck .exe
2007-12-22 12:12 . 2007-12-25 09:50 45,632 –a—— C:\WINDOWS\system32\taskswitch .exe
2007-12-22 12:04 . 2007-12-25 09:50 49,216 –a—— C:\WINDOWS\system32\Fast .exe
2007-12-13 22:16 . 2007-12-31 13:54 d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-31 19:24 ——— d—–w C:\Program Files\Symantec AntiVirus
2007-12-31 19:24 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-30 05:29 ——— d—–w C:\Program Files\AIM6
2007-12-30 05:28 ——— d—–w C:\Program Files\Common Files\AOL
2007-12-30 05:28 ——— d—–w C:\Program Files\AIM
2007-12-30 05:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-12-30 05:10 ——— d—–w C:\Program Files\MSN Messenger
2007-12-30 04:23 ——— d—–w C:\Program Files\Windows Defender
2007-12-30 04:23 ——— d—–w C:\Program Files\QuickTime
2007-12-30 04:23 ——— d—–w C:\Program Files\DellSupport
2007-12-24 22:50 ——— d—–w C:\Program Files\Roxio
2007-12-24 22:41 ——— d—–w C:\Program Files\Common Files\Roxio Shared
2007-12-24 06:01 ——— d—–w C:\Documents and Settings\Guest\Application Data\Yahoo!
2007-12-24 05:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-12-23 18:52 ——— d–h–r C:\Documents and Settings\USER\Application Data\yahoo!
2007-12-23 00:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\yahoo!
2007-12-14 04:12 ——— d—–w C:\Program Files\Yahoo!
2007-12-13 04:40 ——— d—–w C:\Program Files\FriendBlasterPro
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 23:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
.
—-a-w			57,344 2007-12-27 02:36:32  C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy .exe
—-a-w			50,528 2007-12-27 02:37:32  C:\Program Files\AIM6\aim6 .exe
—-a-w			52,840 2007-12-27 02:36:58  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   460,784 2007-12-27 02:37:20  C:\Program Files\DellSupport\DSAgnt .exe
—-a-w		   479,232 2007-12-27 02:36:00  C:\Program Files\Google\Gmail Notifier\gnotify .exe
—-a-w		   132,496 2007-12-27 02:35:46  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		   217,088 2007-12-27 02:35:57  C:\Program Files\Logitech\Video\LogiTray .exe
—-a-w		 5,674,352 2007-12-29 17:14:00  C:\Program Files\MSN Messenger\msnmsgr .exe
—-a-w		 8,720,384 2007-12-27 02:38:32  C:\Program Files\MySpace\IM\MySpaceIM .exe
—-a-w		   266,240 2007-12-27 02:36:42  C:\Program Files\Print Server\PTP\PSDiagnostic .exe
—-a-w		   282,624 2007-12-27 02:36:59  C:\Program Files\QuickTime\qttask			.exe
—-a-w		   282,624 2007-12-30 06:16:58  C:\Program Files\QuickTime\qttask		  .exe
—-a-w		   282,624 2007-12-30 06:16:58  C:\Program Files\QuickTime\qttask		 .exe
—-a-w		   282,624 2007-12-30 06:16:59  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   282,624 2007-12-30 06:17:00  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   282,624 2007-12-30 06:17:01  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   282,624 2007-12-30 06:17:01  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   282,624 2007-12-30 06:17:02  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   282,624 2007-12-30 06:17:02  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   282,624 2007-12-30 06:17:03  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   282,624 2007-12-30 06:17:03  C:\Program Files\QuickTime\qttask .exe
—-a-w		 1,179,648 2007-12-27 02:35:42  C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc .exe
—-a-w		   125,632 2007-12-27 02:36:58  C:\Program Files\Symantec AntiVirus\VPTray .exe
—-a-w		   866,584 2007-12-27 02:36:50  C:\Program Files\Windows Defender\MSASCui .exe
—-a-w		 4,670,704 2007-12-27 02:38:51  C:\Program Files\Yahoo!\Messenger\YahooMessenger	.exe
—-a-w		 4,670,704 2007-12-30 05:37:45  C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
—-a-w		 4,670,704 2007-12-30 05:37:38  C:\Program Files\Yahoo!\Messenger\YAHOOM~1	  .EXE
—-a-w		 4,670,704 2007-12-30 05:37:30  C:\Program Files\Yahoo!\Messenger\YAHOOM~1	 .EXE
—-a-w		 4,670,704 2007-12-30 05:37:13  C:\Program Files\Yahoo!\Messenger\YAHOOM~1	.EXE
—-a-w		 4,670,704 2007-12-30 05:37:07  C:\Program Files\Yahoo!\Messenger\YAHOOM~1   .EXE
—-a-w		 4,670,704 2007-12-30 05:37:02  C:\Program Files\Yahoo!\Messenger\YAHOOM~1  .EXE
—-a-w		 4,670,704 2007-12-30 05:36:58  C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
—-a-w			15,360 2007-12-31 18:42:54  C:\WINDOWS\system32\ctfmon .exe
—-a-w			49,216 2007-12-25 15:50:17  C:\WINDOWS\system32\Fast .exe
—-a-w			77,824 2007-12-25 15:51:26  C:\WINDOWS\system32\hkcmd .exe
—-a-w		   118,784 2007-12-25 15:51:40  C:\WINDOWS\system32\igfxpers .exe
—-a-w			94,208 2007-12-25 15:51:18  C:\WINDOWS\system32\igfxtray .exe
—-a-w		   221,184 2007-12-27 02:35:54  C:\WINDOWS\system32\LVCOMSX .EXE
—-a-w		   155,648 2007-12-25 15:50:51  C:\WINDOWS\system32\NeroCheck .exe
—-a-w			45,632 2007-12-25 15:50:49  C:\WINDOWS\system32\taskswitch .exe
—-a-w			99,840 2007-12-27 02:36:27  C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2K1 .EXE


– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [ ]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [ ]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [ ]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]
"QdrPack11"="C:\Program Files\QdrPack\QdrPack11.exe" [ ]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]
"AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch .exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoxioDragToDisc"="C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" [ ]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [ ]
"FastUser"="C:\WINDOWS\system32\fast.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [ ]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [ ]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [ ]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [ ]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [ ]
"EPSON Stylus Photo RX500"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.exe" [ ]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-06-08 11:31 29696 C:\WINDOWS\KHALMNPR.Exe]
"EPSON Stylus Photo RX500 (Copy 1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.exe" [ ]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [ ]
"PrintServer Diagnostic"="C:\Program Files\Print Server\PTP\PSDiagnostic.exe" [ ]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [ ]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 17:38 52840]
"vptray"="C:\PROGRA~1\SYMANT~2\VPTray.exe" [2007-03-14 19:49 125632]
"c0463754"="C:\WINDOWS\system32\pwiobbot.dll" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 12:45 36040]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\KEM.exe [2005-10-10 22:41:54]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-09-14 10:02:45]

R1 UDFReadr;UDFReadr;C:\WINDOWS\system32\drivers\UDFReadr.sys [2004-02-26 05:58]
R3 ADM851X;ADM851X USB To Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\ADM851X.SYS [2004-10-27 15:05]
R3 LUsbKbd;Logitech SetPoint USB Keyboard Filter;C:\WINDOWS\system32\Drivers\LUsbKbd.Sys [2004-06-08 11:36]
S3 flash;flash;C:\WINDOWS\system32\drivers\flash.sys [2003-08-29 17:47]

.
Contents of the 'Scheduled Tasks' folder
"2008-01-01 21:03:09 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-01 15:18:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\Logitech\SetPoint\lgscroll.dll
-> C:\Program Files\ArcSoft\Software Suite\PhotoImpression 5\share\pihook.dll
.
Completion time: 2008-01-01 15:19:12
C:\qoobox\ComboFix-quarantined-files.txt 2008-01-01 21:18:58
C:\qoobox\ComboFix2.txt 2007-12-31 19:19:18
.
2007-12-27 23:55:16 — E O F —
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\jreqlgnv.ini
C:\WINDOWS\system32\vtqncsgv.ini
C:\WINDOWS\system32\sokwsqjn.ini
C:\WINDOWS\system32\riampacx.ini
C:\WINDOWS\system32\tobboiwp.ini
C:\WINDOWS\system32\rmbmcvnl.ini
C:\WINDOWS\system32\pwiobbot.dll

Folder::
C:\Program Files\QdrPack

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QdrPack11"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"c0463754"=-


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.


—————————————-


Also run and post the log from this tool:

  • Download RenV.exe by sUBs to your desktop
  • Double click on it to run it
  • It will search your system drive looking for any modified .exe file and will produce a log for you.
  • Please attach this report to your reply (Do not copy and paste)
combofix

ComboFix 07-12-31.4 - USER 2008-01-01 16:09:27.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\USER\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\jreqlgnv.ini
C:\WINDOWS\system32\pwiobbot.dll
C:\WINDOWS\system32\riampacx.ini
C:\WINDOWS\system32\rmbmcvnl.ini
C:\WINDOWS\system32\sokwsqjn.ini
C:\WINDOWS\system32\tobboiwp.ini
C:\WINDOWS\system32\vtqncsgv.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\jreqlgnv.ini
C:\WINDOWS\system32\riampacx.ini
C:\WINDOWS\system32\rmbmcvnl.ini
C:\WINDOWS\system32\sokwsqjn.ini
C:\WINDOWS\system32\tobboiwp.ini
C:\WINDOWS\system32\vtqncsgv.ini

.
((((((((((((((((((((((((( Files Created from 2007-12-01 to 2008-01-01 )))))))))))))))))))))))))))))))
.

2007-12-31 15:37 . 2007-12-31 15:37 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-12-31 15:37 . 2007-12-31 15:37 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-31 13:03 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-12-31 12:43 . 2007-12-31 12:44 d——– C:\WINDOWS\ERUNT
2007-12-29 22:20 . 2007-12-29 22:20 256 –a—— C:\Documents and Settings\USER\pool.bin
2007-12-26 19:33 . 2007-12-26 19:33 d——– C:\Documents and Settings\USER\Application Data\Lavasoft
2007-12-26 19:32 . 2007-12-26 19:32 d——– C:\Program Files\Lavasoft
2007-12-26 19:27 . 2007-12-26 19:27 d——– C:\Program Files\Webroot
2007-12-26 19:27 . 2003-10-15 23:52 348,160 –a—— C:\WINDOWS\unSpySweeper.exe
2007-12-26 03:00 . 2007-12-26 03:00 d——– C:\Program Files\MSXML 6.0
2007-12-25 14:26 . 2007-12-30 00:23 d——– C:\VundoFix Backups
2007-12-24 17:38 . 2007-12-24 17:38 d——– C:\Documents and Settings\USER\Application Data\Blackberry Desktop
2007-12-24 17:02 . 2007-12-29 22:36 256 –a—— C:\WINDOWS\system32\pool.bin
2007-12-24 17:01 . 2007-12-24 17:01 d——– C:\Documents and Settings\USER\Application Data\Research In Motion
2007-12-24 16:39 . 2007-12-24 16:39 d——– C:\Program Files\Common Files\Sonic Shared
2007-12-24 16:29 . 2007-01-18 10:24 26,496 -ra—— C:\WINDOWS\system32\drivers\RimSerial.sys
2007-12-24 16:27 . 2007-12-24 16:27 d——– C:\Program Files\Common Files\Research In Motion
2007-12-24 16:26 . 2007-12-24 16:26 d——– C:\Program Files\Research In Motion
2007-12-24 00:28 . 2007-12-24 00:28 d——– C:\Documents and Settings\Guest\Application Data\Roxio
2007-12-23 11:41 . 2007-12-31 12:42 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2007-12-22 12:14 . 2007-12-25 09:51 118,784 –a—— C:\WINDOWS\system32\igfxpers .exe
2007-12-22 12:14 . 2007-12-25 09:51 94,208 –a—— C:\WINDOWS\system32\igfxtray .exe
2007-12-22 12:14 . 2007-12-25 09:51 77,824 –a—— C:\WINDOWS\system32\hkcmd .exe
2007-12-22 12:13 . 2007-12-26 20:35 221,184 –a—— C:\WINDOWS\system32\LVCOMSX .EXE
2007-12-22 12:13 . 2007-12-25 09:50 155,648 –a—— C:\WINDOWS\system32\NeroCheck .exe
2007-12-22 12:12 . 2007-12-25 09:50 45,632 –a—— C:\WINDOWS\system32\taskswitch .exe
2007-12-22 12:04 . 2007-12-25 09:50 49,216 –a—— C:\WINDOWS\system32\Fast .exe
2007-12-13 22:16 . 2007-12-31 13:54 d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-31 19:24 ——— d—–w C:\Program Files\Symantec AntiVirus
2007-12-31 19:24 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-30 05:29 ——— d—–w C:\Program Files\AIM6
2007-12-30 05:28 ——— d—–w C:\Program Files\Common Files\AOL
2007-12-30 05:28 ——— d—–w C:\Program Files\AIM
2007-12-30 05:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-12-30 05:10 ——— d—–w C:\Program Files\MSN Messenger
2007-12-30 04:23 ——— d—–w C:\Program Files\Windows Defender
2007-12-30 04:23 ——— d—–w C:\Program Files\QuickTime
2007-12-30 04:23 ——— d—–w C:\Program Files\DellSupport
2007-12-24 22:50 ——— d—–w C:\Program Files\Roxio
2007-12-24 22:41 ——— d—–w C:\Program Files\Common Files\Roxio Shared
2007-12-24 06:01 ——— d—–w C:\Documents and Settings\Guest\Application Data\Yahoo!
2007-12-24 05:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-12-23 18:52 ——— d–h–r C:\Documents and Settings\USER\Application Data\yahoo!
2007-12-23 00:00 ——— d—–w C:\Documents and Settings\All Users\Application Data\yahoo!
2007-12-14 04:12 ——— d—–w C:\Program Files\Yahoo!
2007-12-13 04:40 ——— d—–w C:\Program Files\FriendBlasterPro
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 23:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
.
—-a-w			57,344 2007-12-27 02:36:32  C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy .exe
—-a-w			50,528 2007-12-27 02:37:32  C:\Program Files\AIM6\aim6 .exe
—-a-w			52,840 2007-12-27 02:36:58  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   460,784 2007-12-27 02:37:20  C:\Program Files\DellSupport\DSAgnt .exe
—-a-w		   479,232 2007-12-27 02:36:00  C:\Program Files\Google\Gmail Notifier\gnotify .exe
—-a-w		   132,496 2007-12-27 02:35:46  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		   217,088 2007-12-27 02:35:57  C:\Program Files\Logitech\Video\LogiTray .exe
—-a-w		 5,674,352 2007-12-29 17:14:00  C:\Program Files\MSN Messenger\msnmsgr .exe
—-a-w		 8,720,384 2007-12-27 02:38:32  C:\Program Files\MySpace\IM\MySpaceIM .exe
—-a-w		   266,240 2007-12-27 02:36:42  C:\Program Files\Print Server\PTP\PSDiagnostic .exe
—-a-w		   282,624 2007-12-27 02:36:59  C:\Program Files\QuickTime\qttask			.exe
—-a-w		   282,624 2007-12-30 06:16:58  C:\Program Files\QuickTime\qttask		  .exe
—-a-w		   282,624 2007-12-30 06:16:58  C:\Program Files\QuickTime\qttask		 .exe
—-a-w		   282,624 2007-12-30 06:16:59  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   282,624 2007-12-30 06:17:00  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   282,624 2007-12-30 06:17:01  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   282,624 2007-12-30 06:17:01  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   282,624 2007-12-30 06:17:02  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   282,624 2007-12-30 06:17:02  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   282,624 2007-12-30 06:17:03  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   282,624 2007-12-30 06:17:03  C:\Program Files\QuickTime\qttask .exe
—-a-w		 1,179,648 2007-12-27 02:35:42  C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc .exe
—-a-w		   125,632 2007-12-27 02:36:58  C:\Program Files\Symantec AntiVirus\VPTray .exe
—-a-w		   866,584 2007-12-27 02:36:50  C:\Program Files\Windows Defender\MSASCui .exe
—-a-w		 4,670,704 2007-12-27 02:38:51  C:\Program Files\Yahoo!\Messenger\YahooMessenger	.exe
—-a-w		 4,670,704 2007-12-30 05:37:45  C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
—-a-w		 4,670,704 2007-12-30 05:37:38  C:\Program Files\Yahoo!\Messenger\YAHOOM~1	  .EXE
—-a-w		 4,670,704 2007-12-30 05:37:30  C:\Program Files\Yahoo!\Messenger\YAHOOM~1	 .EXE
—-a-w		 4,670,704 2007-12-30 05:37:13  C:\Program Files\Yahoo!\Messenger\YAHOOM~1	.EXE
—-a-w		 4,670,704 2007-12-30 05:37:07  C:\Program Files\Yahoo!\Messenger\YAHOOM~1   .EXE
—-a-w		 4,670,704 2007-12-30 05:37:02  C:\Program Files\Yahoo!\Messenger\YAHOOM~1  .EXE
—-a-w		 4,670,704 2007-12-30 05:36:58  C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
—-a-w			15,360 2007-12-31 18:42:54  C:\WINDOWS\system32\ctfmon .exe
—-a-w			49,216 2007-12-25 15:50:17  C:\WINDOWS\system32\Fast .exe
—-a-w			77,824 2007-12-25 15:51:26  C:\WINDOWS\system32\hkcmd .exe
—-a-w		   118,784 2007-12-25 15:51:40  C:\WINDOWS\system32\igfxpers .exe
—-a-w			94,208 2007-12-25 15:51:18  C:\WINDOWS\system32\igfxtray .exe
—-a-w		   221,184 2007-12-27 02:35:54  C:\WINDOWS\system32\LVCOMSX .EXE
—-a-w		   155,648 2007-12-25 15:50:51  C:\WINDOWS\system32\NeroCheck .exe
—-a-w			45,632 2007-12-25 15:50:49  C:\WINDOWS\system32\taskswitch .exe
—-a-w			99,840 2007-12-27 02:36:27  C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2K1 .EXE


– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [ ]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [ ]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [ ]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
"AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch .exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoxioDragToDisc"="C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" [ ]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [ ]
"FastUser"="C:\WINDOWS\system32\fast.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [ ]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [ ]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [ ]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [ ]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [ ]
"EPSON Stylus Photo RX500"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.exe" [ ]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-06-08 11:31 29696 C:\WINDOWS\KHALMNPR.Exe]
"EPSON Stylus Photo RX500 (Copy 1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.exe" [ ]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [ ]
"PrintServer Diagnostic"="C:\Program Files\Print Server\PTP\PSDiagnostic.exe" [ ]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [ ]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 17:38 52840]
"vptray"="C:\PROGRA~1\SYMANT~2\VPTray.exe" [2007-03-14 19:49 125632]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 12:45 36040]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\KEM.exe [2005-10-10 22:41:54]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-09-14 10:02:45]

R1 UDFReadr;UDFReadr;C:\WINDOWS\system32\drivers\UDFReadr.sys [2004-02-26 05:58]
R3 ADM851X;ADM851X USB To Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\ADM851X.SYS [2004-10-27 15:05]
R3 LUsbKbd;Logitech SetPoint USB Keyboard Filter;C:\WINDOWS\system32\Drivers\LUsbKbd.Sys [2004-06-08 11:36]
S3 flash;flash;C:\WINDOWS\system32\drivers\flash.sys [2003-08-29 17:47]

.
Contents of the 'Scheduled Tasks' folder
"2008-01-01 21:03:09 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-01 16:11:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-01 16:11:50
C:\qoobox\ComboFix-quarantined-files.txt 2008-01-01 22:11:27
C:\qoobox\ComboFix2.txt 2008-01-01 21:19:13
C:\qoobox\ComboFix3.txt 2007-12-31 19:19:18
.
2007-12-27 23:55:16 — E O F —


new hijack report

Logfile of HijackThis v1.99.1
Scan saved at 4:12:19 PM, on 1/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\AIM6\aim6 .exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\system32\fast.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P24 "EPSON Stylus Photo RX500" /O14 "IP_LKD160A2_P1" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500 (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P33 "EPSON Stylus Photo RX500 (Copy 1)" /O6 "USB002" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PrintServer Diagnostic] C:\Program Files\Print Server\PTP\PSDiagnostic.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch .exe"
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Betus Poker - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\BETUSP~1\client.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.net\PartyPokerNet\RunPF.exe
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.net\PartyPokerNet\RunPF.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {528C14CD-CF9E-489C-A365-5999F17B69B9} (LightSurfUploadCtl Class) - http://pictures.sprintpcs.com/activex/Ligh…loadControl.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1124668838993
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.dotphoto.com/ImageUploader4.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.dotphoto.com/DPImageUploader.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} - http://static.zangocash.com/cab/Seekmo/ie/…5d3c47945c52d3d
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.dotphoto.com/XUpload.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InteractiveLogon - Unknown owner - C:\WINDOWS\system32\Fast.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe


and ive attached the renv file

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI