This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HELP! inet speed monitor, vundo, bifrose, trats&#

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am running Windows XP SP2.
A few days ago popups started appearing automatically with 'internet speed monitor' in the title bar. Both Norton AV and Ad-Aware were not able to find anything. I got rid of qdrmodule and its cousins and the popups stopped,but since then, Norton has been lighting up with other infections and doesnt seem be able to clear them: backdoor.bifrose, vundo, w32.trats!info, purityscan, etc. No matter how many times i scan, these keep coming up. Also, all of a sudden, my computer is running much slower than normal. I have scanned in safe mode and have put the drive in another machine and scanned it there, yet when i boot up with it, it still is very much infected.

any help would be greatly appreciated.

here is my hijack this log:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [MAFWTaskbarApp] C:\WINDOWS\system32\MAFWTray.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - file://C:\install.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…ol_v1-0-3-9.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093233305013
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155496434812
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - https://brewx.qualcomm.com/noauth/cms/BREW_….0.1/isetup.cab
O16 - DPF: {B2FCED61-570E-11D3-B160-00A0C9E70E84} (OmniForm Form Control) - https://www4.lsac.org/OIFActiveX/ofmctlnew.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/bejeweled…aploader_v6.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
Hi, and Welcome to WhatTheTech :)

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

As I am still training, my posts to you will be checked by an Expert member. This will ensure that all advice and instructions I give you are accurate and safe. This may mean that my replies may take a little longer.

jpshortstuff
Hi

Before we begin, please rename HijackThis.exe to scanner.exe. Next time you post a log, please include the whole log, that includes all the information at the top.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.



Download ComboFix by sUBs from here or here

**Save it to your desktop**

Double click on ComboFix.exe & follow the prompts.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall


Thanks,

jpshortstuff
thanks for the quick response!

here is the combofix log:

ComboFix 08-01-04.1 - JMS44 2008-01-06 19:40:16.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.169 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\JMS44\Application Data\YSTEM3~1
C:\Documents and Settings\JMS44\Application Data\YSTEM3~1\?ystem32\
C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
C:\Program Files\ISM
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\Temporary
C:\Program Files\WinAble
C:\WINDOWS\stem~1
C:\WINDOWS\system32\awtqn.dll
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\SYSTEM32\nqtwa.ini
C:\WINDOWS\SYSTEM32\nqtwa.ini2
C:\WINDOWS\system32\wnstssv32.exe
C:\WINDOWS\system32\wnsxs~1

.
((((((((((((((((((((((((( Files Created from 2007-12-07 to 2008-01-07 )))))))))))))))))))))))))))))))
.

2008-01-06 19:38 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-02 23:49 . 2008-01-02 23:49 d——– C:\Documents and Settings\All Users\Application Data\ESET
2008-01-01 16:45 . 2007-05-29 13:55 22,112 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.sys
2008-01-01 16:45 . 2007-05-29 13:55 10,592 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.cat
2008-01-01 16:45 . 2007-05-29 13:55 705 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.inf
2007-12-24 13:30 . 2007-12-24 13:30 15,360 –a—— C:\WINDOWS\SYSTEM32\ctfmon .exe
2007-12-23 23:29 . 2008-01-06 19:36 d——– C:\trend micro hijack this
2007-12-23 22:06 . 2007-12-23 22:06 d——– C:\Program Files\Lavasoft
2007-12-23 22:06 . 2007-12-23 22:06 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-23 22:04 . 2007-12-23 22:05 21,216,112 –a—— C:\aaw2007.exe
2007-12-23 12:14 . 2007-12-23 12:20 10,740 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.CAT
2007-12-23 12:14 . 2007-12-23 12:20 805 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.INF
2007-12-23 11:57 . 2007-12-31 21:19 155,648 –a—— C:\WINDOWS\SYSTEM32\MAFWTray .exe
2007-12-22 10:36 . 2007-12-22 11:02 d——– C:\surf vids
2007-12-13 21:23 . 2007-12-13 21:23 173,286 –a—— C:\kitchenaide.gif
2007-12-10 21:49 . 2007-12-10 21:50 13,413,048 –a—— C:\Google_Earth_BZXD.exe
2007-12-07 20:16 . 2007-12-23 11:26 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-07 20:16 . 2007-12-07 20:16 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-07 00:09 . 2007-12-07 00:09 1,158 –a—— C:\WINDOWS\mozver.dat
2007-12-07 00:08 . 2007-12-07 00:08 0 –a—— C:\WINDOWS\nsreg.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 20:27 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-04 03:15 ——— d—–w C:\Program Files\Norton AntiVirus
2008-01-01 21:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-01 17:02 ——— d—–w C:\Program Files\QuickTime
2007-12-24 18:29 158,208 —-a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\MSConfig .exe
2007-12-24 03:05 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-23 17:20 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-23 17:20 ——— d—–w C:\Program Files\Symantec
2007-12-14 02:22 ——— d—–w C:\Documents and Settings\JMS44\Application Data\Canon
2007-12-11 02:51 ——— d—–w C:\Program Files\Google
2007-12-01 04:57 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-12-01 04:57 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-12-01 04:57 279,088 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-12-01 04:57 10,545 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-12-01 04:57 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-12-01 04:57 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-12-01 04:57 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-27 02:39 ——— d—–w C:\Program Files\Netflix
2007-11-27 02:18 ——— d—–w C:\Documents and Settings\JMS44\Application Data\dvdcss
2007-11-14 20:06 30,728 —-a-w C:\WINDOWS\system32\drivers\epfwtdir.sys
2007-11-14 20:04 27,656 —-a-w C:\WINDOWS\system32\drivers\easdrv.sys
2007-11-14 20:03 33,800 —-a-w C:\WINDOWS\system32\drivers\eamon.sys
2007-10-20 19:42 3,024,669 —-a-w C:\cwRsync_2.0.10_Installer.zip
2007-10-20 16:12 143,308,512 —-a-w C:\TrueImage11_d_en.exe
2006-11-25 23:23 71,600 —-a-w C:\Documents and Settings\JMS44\Application Data\GDIPFONTCACHEV1.DAT
2004-07-14 20:06 609 —-a-w C:\Program Files\Common Files\alert.vbs
2003-05-21 17:31 951 —-a-w C:\Program Files\INSTALL.LOG
2002-09-14 21:52 779,276,400 —-a-w C:\Documents and Settings\JMS44\ambient 1.bin
2002-09-14 21:49 776,025,936 —-a-w C:\Documents and Settings\JMS44\bill laswell.bin
2002-09-14 21:39 598,005,408 —-a-w C:\Documents and Settings\JMS44\dopeheadz drums.bin
2002-09-14 21:35 706,315,008 —-a-w C:\Documents and Settings\JMS44\primitive instruments.bin
2001-05-10 14:04 162,304 —-a-w C:\Program Files\UNWISE.EXE
.
—-a-w		   905,056 2008-01-01 02:19:42  C:\Program Files\Acronis\TrueImageHome\TimounterMonitor .exe
—-a-w		 2,595,480 2008-01-01 02:19:42  C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor .exe
—-a-w		   140,568 2008-01-01 02:19:48  C:\Program Files\Common Files\Acronis\Schedule2\schedhlp .exe
—-a-w			84,640 2008-01-01 02:20:14  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   270,336 2008-01-01 02:19:04  C:\Program Files\Dell\Support\Alert\bin\DAMon .exe
—-a-w		 1,694,208 2008-01-01 02:20:16  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   282,624 2008-01-01 04:10:34  C:\Program Files\QuickTime\qttask		  .exe
—-a-w		   282,624 2008-01-01 04:10:35  C:\Program Files\QuickTime\qttask		 .exe
—-a-w		   282,624 2008-01-01 04:10:36  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   282,624 2008-01-01 04:10:37  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   282,624 2008-01-01 04:10:38  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   282,624 2008-01-01 04:10:39  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   282,624 2008-01-01 04:10:40  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   282,624 2008-01-01 04:10:41  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   282,624 2008-01-01 04:09:45  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   282,624 2008-01-01 04:10:42  C:\Program Files\QuickTime\qttask .exe
—-a-w		   679,936 2008-01-01 02:19:00  C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD .exe
—-a-w			49,152 2008-01-01 02:19:13  C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2 .exe
—-a-w		   158,208 2007-12-24 18:29:23  C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\MSConfig .exe
—-a-w			15,360 2007-12-24 18:30:19  C:\WINDOWS\SYSTEM32\ctfmon .exe
—-a-w		   155,648 2008-01-01 02:19:23  C:\WINDOWS\SYSTEM32\MAFWTray .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0a6678ea-889b-4d12-8e8c-60c44fd580ef}]
C:\WINDOWS\system32\natrsgvv.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\Money Express.exe" [ ]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"NvMediaCenter"="C:\WINDOWS\system32\NVMCTRAY.DLL" [2003-07-28 14:19 49152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [ ]
"Dell|Alert"="C:\Program Files\Dell\Support\Alert\bin\DAMon.exe" [ ]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 14:19 4841472]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"MAFWTaskbarApp"="C:\WINDOWS\system32\MAFWTray.exe" [ ]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 02:56 158208]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [ ]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [ ]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [ ]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 14:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 14:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"nwiz"="nwiz.exe" [2003-07-28 14:19 323584 C:\WINDOWS\SYSTEM32\nwiz.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-03 22:29 84640]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2008-01-03 22:29 26248]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [ ]

C:\Documents and Settings\JMS44\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe [2006-05-23 16:17:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-02-24 18:59:00]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-10-20 22:17:28]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"SpecifyDefaultButtons"= 1 (0x1)
"Btn_Search"= 2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnlllk]
nnnlllk.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
2002-08-03 00:34 155648 –a—— C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ekrn"=2 (0x2)
"EhttpSrv"=3 (0x3)

R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2007-10-20 11:18]
R1 Asapi;Asapi;C:\WINDOWS\system32\drivers\Asapi.sys [2000-01-08 08:22]
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2007-11-14 15:06]
R2 TryAndDecideService;Acronis Try And Decide Service;"C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe" [2007-09-14 08:12]
S3 CW50;CW50 Device;C:\WINDOWS\system32\DRIVERS\CW50.sys [2001-07-26 21:26]
S3 DCamUSBVeo532;Veo Web Camera;C:\WINDOWS\system32\Drivers\ubVeo532.sys [2002-07-01 18:30]
S3 echogals;Gina20 Service;C:\WINDOWS\system32\drivers\echogals.sys [2003-06-04 14:13]
S3 LMASFltr;LMASFltr;C:\WINDOWS\system32\drivers\LMASFltr.sys []
S3 MMAUSB;M-Audio USB ASIO Driver;C:\WINDOWS\system32\Drivers\MMAUSB.SYS []
S3 MTK;Media Technology Kernel Driver;C:\WINDOWS\system32\Drivers\mtk.sys []
S3 USB88LDR;Midiman USB MidiSport 8x8/s Loader;C:\WINDOWS\system32\drivers\usb88ldr.sys [2002-04-16 11:21]
S3 USBMIDIM;M-Audio USB MidiSport Midi Kernel Driver;C:\WINDOWS\system32\drivers\usbmidim.sys [2004-08-10 19:09]
S3 USBMM2X4;M-Audio USB MidiSport 2x4 USB Driver;C:\WINDOWS\system32\drivers\usbmm2x4.sys [2004-08-10 19:09]
S3 USBMM8X8;Midiman USB MidiSport 8x8/s Midi Driver;C:\WINDOWS\system32\drivers\usbmm8x8.sys [2002-04-16 11:21]
S4 hpt3xx;hpt3xx;C:\WINDOWS\system32\DRIVERS\hpt3xx.sys [2001-08-17 13:52]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-23 17:11:56 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - JMS44.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-06 19:50:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-06 19:56:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-07 00:55:57


here is the hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:04:21 PM, on 1/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\EditPlus 2\editplus.exe
C:\trend micro hijack this\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: {fe085df4-4c06-c8e8-21d4-b988ae8766a0} - {0a6678ea-889b-4d12-8e8c-60c44fd580ef} - C:\WINDOWS\system32\natrsgvv.dll (file missing)
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [MAFWTaskbarApp] C:\WINDOWS\system32\MAFWTray.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - S-1-5-18 Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe (User 'Default user')
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - file://C:\install.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…ol_v1-0-3-9.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093233305013
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155496434812
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - https://brewx.qualcomm.com/noauth/cms/BREW_….0.1/isetup.cab
O16 - DPF: {B2FCED61-570E-11D3-B160-00A0C9E70E84} (OmniForm Form Control) - https://www4.lsac.org/OIFActiveX/ofmctlnew.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/bejeweled…aploader_v6.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O20 - Winlogon Notify: nnnlllk - nnnlllk.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

–
End of file - 9581 bytes
Hi

You appear to be running two antivirus programs, NOD32 and Norton/Symantec AntiVirus. Running two AntiVirus as on-access (real-time) scanners can cause conflicts between the two programs, and will also slow your computer down. I strongly recommend you uninstall one of these programs. You can run an online scan with Kaspersky or Housecall whenever you need a second opinion.



1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\natrsgvv.dll
C:\WINDOWS\system32\nnnlllk.dll

Driver::
LMASFltr
MMAUSB
MTK

RenV::
—-a-w		   905,056 2008-01-01 02:19:42  C:\Program Files\Acronis\TrueImageHome\TimounterMonitor .exe
—-a-w		   140,568 2008-01-01 02:19:48  C:\Program Files\Common Files\Acronis\Schedule2\schedhlp .exe
—-a-w			84,640 2008-01-01 02:20:14  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   270,336 2008-01-01 02:19:04  C:\Program Files\Dell\Support\Alert\bin\DAMon .exe
—-a-w		 1,694,208 2008-01-01 02:20:16  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   282,624 2008-01-01 04:10:34  C:\Program Files\QuickTime\qttask		  .exe
—-a-w		   282,624 2008-01-01 04:10:35  C:\Program Files\QuickTime\qttask		 .exe
—-a-w		   282,624 2008-01-01 04:10:36  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   282,624 2008-01-01 04:10:37  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   282,624 2008-01-01 04:10:38  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   282,624 2008-01-01 04:10:39  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   282,624 2008-01-01 04:10:40  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   282,624 2008-01-01 04:10:41  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   282,624 2008-01-01 04:09:45  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   282,624 2008-01-01 04:10:42  C:\Program Files\QuickTime\qttask .exe
—-a-w		   679,936 2008-01-01 02:19:00  C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD .exe
—-a-w			49,152 2008-01-01 02:19:13  C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2 .exe
—-a-w		   158,208 2007-12-24 18:29:23  C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\MSConfig .exe
—-a-w			15,360 2007-12-24 18:30:19  C:\WINDOWS\SYSTEM32\ctfmon .exe
—-a-w		   155,648 2008-01-01 02:19:23  C:\WINDOWS\SYSTEM32\MAFWTray .exe

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0a6678ea-889b-4d12-8e8c-60c44fd580ef}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnlllk]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}]

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Please describe how your computer is running at the moment.

Thanks,

jpshortstuff
hi

I have uninstalled the ESET antivirus and ran the combofix script.
it seems that popups are no longer appearing on their own. It still is taking longer to boot up than it did before infection; after logging in, it sits on my desktop image for a while before icons start appearing. then, it takes a while for the real icon images to appear for each icon. After the computer has booted, i hear and see my harddrive being accessed continually even though it is sitting idle.

here is the combofix log:

ComboFix 08-01-04.1 - JMS44 2008-01-07 22:13:30.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.188 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\JMS44\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\natrsgvv.dll
C:\WINDOWS\system32\nnnlllk.dll
.

((((((((((((((((((((((((( Files Created from 2007-12-08 to 2008-01-08 )))))))))))))))))))))))))))))))
.

2008-01-06 19:38 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-02 23:49 . 2008-01-02 23:49 d——– C:\Documents and Settings\All Users\Application Data\ESET
2008-01-01 16:45 . 2007-05-29 13:55 22,112 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.sys
2008-01-01 16:45 . 2007-05-29 13:55 10,592 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.cat
2008-01-01 16:45 . 2007-05-29 13:55 705 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.inf
2007-12-24 13:30 . 2007-12-24 13:30 15,360 –a—— C:\WINDOWS\SYSTEM32\ctfmon .exe
2007-12-23 23:29 . 2008-01-06 20:04 d——– C:\trend micro hijack this
2007-12-23 22:06 . 2007-12-23 22:06 d——– C:\Program Files\Lavasoft
2007-12-23 22:06 . 2007-12-23 22:06 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-23 22:04 . 2007-12-23 22:05 21,216,112 –a—— C:\aaw2007.exe
2007-12-23 12:14 . 2007-12-23 12:20 10,740 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.CAT
2007-12-23 12:14 . 2007-12-23 12:20 805 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.INF
2007-12-23 11:57 . 2007-12-31 21:19 155,648 –a—— C:\WINDOWS\SYSTEM32\MAFWTray .exe
2007-12-22 10:36 . 2007-12-22 11:02 d——– C:\surf vids
2007-12-13 21:23 . 2007-12-13 21:23 173,286 –a—— C:\kitchenaide.gif
2007-12-10 21:49 . 2007-12-10 21:50 13,413,048 –a—— C:\Google_Earth_BZXD.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 20:27 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-04 03:15 ——— d—–w C:\Program Files\Norton AntiVirus
2008-01-01 21:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-01 17:02 ——— d—–w C:\Program Files\QuickTime
2007-12-24 18:29 158,208 —-a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\MSConfig .exe
2007-12-24 03:05 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-23 17:20 60,800 —-a-w C:\WINDOWS\SYSTEM32\S32EVNT1.DLL
2007-12-23 17:20 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-23 17:20 ——— d—–w C:\Program Files\Symantec
2007-12-14 02:22 ——— d—–w C:\Documents and Settings\JMS44\Application Data\Canon
2007-12-11 02:51 ——— d—–w C:\Program Files\Google
2007-12-01 04:57 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-12-01 04:57 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-12-01 04:57 279,088 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-12-01 04:57 10,545 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-12-01 04:57 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-12-01 04:57 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-12-01 04:57 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-27 02:39 ——— d—–w C:\Program Files\Netflix
2007-11-27 02:18 ——— d—–w C:\Documents and Settings\JMS44\Application Data\dvdcss
2007-10-31 00:55 625,032 —-a-w C:\WINDOWS\SYSTEM32\SymNeti.dll
2007-10-31 00:55 242,056 —-a-w C:\WINDOWS\SYSTEM32\SymRedir.dll
2007-10-20 19:42 3,024,669 —-a-w C:\cwRsync_2.0.10_Installer.zip
2007-10-20 16:37 1,880,856 —-a-w C:\WINDOWS\SYSTEM32\AutoPartNt.exe
2007-10-20 16:12 143,308,512 —-a-w C:\TrueImage11_d_en.exe
2006-11-25 23:23 71,600 —-a-w C:\Documents and Settings\JMS44\Application Data\GDIPFONTCACHEV1.DAT
2004-07-14 20:06 609 —-a-w C:\Program Files\Common Files\alert.vbs
2003-05-21 17:31 951 —-a-w C:\Program Files\INSTALL.LOG
2002-09-14 21:52 779,276,400 —-a-w C:\Documents and Settings\JMS44\ambient 1.bin
2002-09-14 21:49 776,025,936 —-a-w C:\Documents and Settings\JMS44\bill laswell.bin
2002-09-14 21:39 598,005,408 —-a-w C:\Documents and Settings\JMS44\dopeheadz drums.bin
2002-09-14 21:35 706,315,008 —-a-w C:\Documents and Settings\JMS44\primitive instruments.bin
2001-05-10 14:04 162,304 —-a-w C:\Program Files\UNWISE.EXE
.
——w		   905,056 2008-01-01 02:19:42  C:\Program Files\Acronis\TrueImageHome\TimounterMonitor .exe
—-a-w		 2,595,480 2008-01-01 02:19:42  C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor .exe
—-a-w		   140,568 2008-01-01 02:19:48  C:\Program Files\Common Files\Acronis\Schedule2\schedhlp .exe
—-a-w			84,640 2008-01-01 02:20:14  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   270,336 2008-01-01 02:19:04  C:\Program Files\Dell\Support\Alert\bin\DAMon .exe
—-a-w		 1,694,208 2008-01-01 02:20:16  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   282,624 2008-01-01 04:10:34  C:\Program Files\QuickTime\qttask		  .exe
—-a-w		   282,624 2008-01-01 04:10:35  C:\Program Files\QuickTime\qttask		 .exe
—-a-w		   282,624 2008-01-01 04:10:36  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   282,624 2008-01-01 04:10:37  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   282,624 2008-01-01 04:10:38  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   282,624 2008-01-01 04:10:39  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   282,624 2008-01-01 04:10:40  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   282,624 2008-01-01 04:10:41  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   282,624 2008-01-01 04:09:45  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   282,624 2008-01-01 04:10:42  C:\Program Files\QuickTime\qttask .exe
—-a-w		   679,936 2008-01-01 02:19:00  C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD .exe
—-a-w			49,152 2008-01-01 02:19:13  C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2 .exe
—-a-w		   158,208 2007-12-24 18:29:23  C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\MSConfig .exe
—-a-w			15,360 2007-12-24 18:30:19  C:\WINDOWS\SYSTEM32\ctfmon .exe
—-a-w		   155,648 2008-01-01 02:19:23  C:\WINDOWS\SYSTEM32\MAFWTray .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\Money Express.exe" [ ]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"NvMediaCenter"="C:\WINDOWS\system32\NVMCTRAY.DLL" [2003-07-28 14:19 49152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [ ]
"Dell|Alert"="C:\Program Files\Dell\Support\Alert\bin\DAMon.exe" [ ]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 14:19 4841472]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"MAFWTaskbarApp"="C:\WINDOWS\system32\MAFWTray.exe" [ ]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 02:56 158208]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [ ]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [ ]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [ ]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 14:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 14:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"nwiz"="nwiz.exe" [2003-07-28 14:19 323584 C:\WINDOWS\SYSTEM32\nwiz.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-03 22:29 84640]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2008-01-03 22:29 26248]

C:\Documents and Settings\JMS44\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe [2006-05-23 16:17:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-02-24 18:59:00]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-10-20 22:17:28]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"SpecifyDefaultButtons"= 1 (0x1)
"Btn_Search"= 2 (0x2)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
2002-08-03 00:34 155648 –a—— C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ekrn"=2 (0x2)
"EhttpSrv"=3 (0x3)

R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2007-10-20 11:18]
R1 Asapi;Asapi;C:\WINDOWS\system32\drivers\Asapi.sys [2000-01-08 08:22]
R2 TryAndDecideService;Acronis Try And Decide Service;"C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe" [2007-09-14 08:12]
S3 CW50;CW50 Device;C:\WINDOWS\system32\DRIVERS\CW50.sys [2001-07-26 21:26]
S3 DCamUSBVeo532;Veo Web Camera;C:\WINDOWS\system32\Drivers\ubVeo532.sys [2002-07-01 18:30]
S3 echogals;Gina20 Service;C:\WINDOWS\system32\drivers\echogals.sys [2003-06-04 14:13]
S3 USB88LDR;Midiman USB MidiSport 8x8/s Loader;C:\WINDOWS\system32\drivers\usb88ldr.sys [2002-04-16 11:21]
S3 USBMIDIM;M-Audio USB MidiSport Midi Kernel Driver;C:\WINDOWS\system32\drivers\usbmidim.sys [2004-08-10 19:09]
S3 USBMM2X4;M-Audio USB MidiSport 2x4 USB Driver;C:\WINDOWS\system32\drivers\usbmm2x4.sys [2004-08-10 19:09]
S3 USBMM8X8;Midiman USB MidiSport 8x8/s Midi Driver;C:\WINDOWS\system32\drivers\usbmm8x8.sys [2002-04-16 11:21]
S4 hpt3xx;hpt3xx;C:\WINDOWS\system32\DRIVERS\hpt3xx.sys [2001-08-17 13:52]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-23 17:11:56 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - JMS44.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-07 22:22:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-07 22:27:27 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-08 03:27:22
ComboFix2.txt 2008-01-07 00:56:03


and here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:39:51 PM, on 1/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\trend micro hijack this\scanner.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [MAFWTaskbarApp] C:\WINDOWS\system32\MAFWTray.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - file://C:\install.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…ol_v1-0-3-9.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093233305013
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155496434812
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - https://brewx.qualcomm.com/noauth/cms/BREW_….0.1/isetup.cab
O16 - DPF: {B2FCED61-570E-11D3-B160-00A0C9E70E84} (OmniForm Form Control) - https://www4.lsac.org/OIFActiveX/ofmctlnew.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

–
End of file - 8767 bytes


Thanks!
Hi

We need to do another CFScript.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

RenV::
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor .exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor .exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp .exe
C:\Program Files\Common Files\Symantec Shared\ccApp .exe
C:\Program Files\Dell\Support\Alert\bin\DAMon .exe
C:\Program Files\Messenger\msmsgs .exe
C:\Program Files\QuickTime\qttask		  .exe
C:\Program Files\QuickTime\qttask		 .exe
C:\Program Files\QuickTime\qttask		.exe
C:\Program Files\QuickTime\qttask	   .exe
C:\Program Files\QuickTime\qttask	  .exe
C:\Program Files\QuickTime\qttask	 .exe
C:\Program Files\QuickTime\qttask	.exe
C:\Program Files\QuickTime\qttask   .exe
C:\Program Files\QuickTime\qttask  .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD .exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2 .exe
C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\MSConfig .exe
C:\WINDOWS\SYSTEM32\ctfmon .exe
C:\WINDOWS\SYSTEM32\MAFWTray .exe

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Please describe how your computer is running at the moment.

Thanks,

jpshortstuff
hi. combofix did not require a reboot this time. after this scan it is definitely booting faster than before, but still a bit slower than before infection. the constant hard disk access has let up a bit. here are the logs:

combofix:

ComboFix 08-01-04.1 - JMS44 2008-01-09 7:51:34.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.168 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\JMS44\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-12-09 to 2008-01-09 )))))))))))))))))))))))))))))))
.

2008-01-06 19:38 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-02 23:49 . 2008-01-02 23:49 d——– C:\Documents and Settings\All Users\Application Data\ESET
2008-01-01 16:45 . 2007-05-29 13:55 22,112 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.sys
2008-01-01 16:45 . 2007-05-29 13:55 10,592 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.cat
2008-01-01 16:45 . 2007-05-29 13:55 705 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.inf
2007-12-24 13:30 . 2007-12-24 13:30 15,360 –a—— C:\WINDOWS\SYSTEM32\ctfmon .exe
2007-12-23 23:29 . 2008-01-07 22:39 d——– C:\trend micro hijack this
2007-12-23 22:06 . 2007-12-23 22:06 d——– C:\Program Files\Lavasoft
2007-12-23 22:06 . 2007-12-23 22:06 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-23 22:04 . 2007-12-23 22:05 21,216,112 –a—— C:\aaw2007.exe
2007-12-23 12:14 . 2007-12-23 12:20 10,740 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.CAT
2007-12-23 12:14 . 2007-12-23 12:20 805 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.INF
2007-12-23 11:57 . 2007-12-31 21:19 155,648 –a—— C:\WINDOWS\SYSTEM32\MAFWTray .exe
2007-12-22 10:36 . 2007-12-22 11:02 d——– C:\surf vids
2007-12-13 21:23 . 2007-12-13 21:23 173,286 –a—— C:\kitchenaide.gif
2007-12-10 21:49 . 2007-12-10 21:50 13,413,048 –a—— C:\Google_Earth_BZXD.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 20:27 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-04 03:15 ——— d—–w C:\Program Files\Norton AntiVirus
2008-01-01 21:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-01 17:02 ——— d—–w C:\Program Files\QuickTime
2007-12-24 18:29 158,208 —-a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\MSConfig .exe
2007-12-24 03:05 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-23 17:20 60,800 —-a-w C:\WINDOWS\SYSTEM32\S32EVNT1.DLL
2007-12-23 17:20 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-23 17:20 ——— d—–w C:\Program Files\Symantec
2007-12-14 02:22 ——— d—–w C:\Documents and Settings\JMS44\Application Data\Canon
2007-12-11 02:51 ——— d—–w C:\Program Files\Google
2007-12-01 04:57 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-12-01 04:57 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-12-01 04:57 279,088 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-12-01 04:57 10,545 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-12-01 04:57 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-12-01 04:57 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-12-01 04:57 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-27 02:39 ——— d—–w C:\Program Files\Netflix
2007-11-27 02:18 ——— d—–w C:\Documents and Settings\JMS44\Application Data\dvdcss
2007-10-31 00:55 625,032 —-a-w C:\WINDOWS\SYSTEM32\SymNeti.dll
2007-10-31 00:55 242,056 —-a-w C:\WINDOWS\SYSTEM32\SymRedir.dll
2007-10-20 19:42 3,024,669 —-a-w C:\cwRsync_2.0.10_Installer.zip
2007-10-20 16:37 1,880,856 —-a-w C:\WINDOWS\SYSTEM32\AutoPartNt.exe
2007-10-20 16:12 143,308,512 —-a-w C:\TrueImage11_d_en.exe
2006-11-25 23:23 71,600 —-a-w C:\Documents and Settings\JMS44\Application Data\GDIPFONTCACHEV1.DAT
2004-07-14 20:06 609 —-a-w C:\Program Files\Common Files\alert.vbs
2003-05-21 17:31 951 —-a-w C:\Program Files\INSTALL.LOG
2002-09-14 21:52 779,276,400 —-a-w C:\Documents and Settings\JMS44\ambient 1.bin
2002-09-14 21:49 776,025,936 —-a-w C:\Documents and Settings\JMS44\bill laswell.bin
2002-09-14 21:39 598,005,408 —-a-w C:\Documents and Settings\JMS44\dopeheadz drums.bin
2002-09-14 21:35 706,315,008 —-a-w C:\Documents and Settings\JMS44\primitive instruments.bin
2001-05-10 14:04 162,304 —-a-w C:\Program Files\UNWISE.EXE
.
——w		   905,056 2008-01-01 02:19:42  C:\Program Files\Acronis\TrueImageHome\TimounterMonitor .exe
—-a-w		 2,595,480 2008-01-01 02:19:42  C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor .exe
—-a-w		   140,568 2008-01-01 02:19:48  C:\Program Files\Common Files\Acronis\Schedule2\schedhlp .exe
—-a-w			84,640 2008-01-01 02:20:14  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   270,336 2008-01-01 02:19:04  C:\Program Files\Dell\Support\Alert\bin\DAMon .exe
—-a-w		 1,694,208 2008-01-01 02:20:16  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   282,624 2008-01-01 04:10:34  C:\Program Files\QuickTime\qttask		  .exe
—-a-w		   282,624 2008-01-01 04:10:35  C:\Program Files\QuickTime\qttask		 .exe
—-a-w		   282,624 2008-01-01 04:10:36  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   282,624 2008-01-01 04:10:37  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   282,624 2008-01-01 04:10:38  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   282,624 2008-01-01 04:10:39  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   282,624 2008-01-01 04:10:40  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   282,624 2008-01-01 04:10:41  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   282,624 2008-01-01 04:09:45  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   282,624 2008-01-01 04:10:42  C:\Program Files\QuickTime\qttask .exe
—-a-w		   679,936 2008-01-01 02:19:00  C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD .exe
—-a-w			49,152 2008-01-01 02:19:13  C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2 .exe
—-a-w		   158,208 2007-12-24 18:29:23  C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\MSConfig .exe
—-a-w			15,360 2007-12-24 18:30:19  C:\WINDOWS\SYSTEM32\ctfmon .exe
—-a-w		   155,648 2008-01-01 02:19:23  C:\WINDOWS\SYSTEM32\MAFWTray .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\Money Express.exe" [ ]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"NvMediaCenter"="C:\WINDOWS\system32\NVMCTRAY.DLL" [2003-07-28 14:19 49152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [ ]
"Dell|Alert"="C:\Program Files\Dell\Support\Alert\bin\DAMon.exe" [ ]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 14:19 4841472]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"MAFWTaskbarApp"="C:\WINDOWS\system32\MAFWTray.exe" [ ]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 02:56 158208]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [ ]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [ ]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [ ]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 14:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 14:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"nwiz"="nwiz.exe" [2003-07-28 14:19 323584 C:\WINDOWS\SYSTEM32\nwiz.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-03 22:29 84640]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2008-01-03 22:29 26248]

C:\Documents and Settings\JMS44\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe [2006-05-23 16:17:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-02-24 18:59:00]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-10-20 22:17:28]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"SpecifyDefaultButtons"= 1 (0x1)
"Btn_Search"= 2 (0x2)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
2002-08-03 00:34 155648 –a—— C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ekrn"=2 (0x2)
"EhttpSrv"=3 (0x3)

R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2007-10-20 11:18]
R1 Asapi;Asapi;C:\WINDOWS\system32\drivers\Asapi.sys [2000-01-08 08:22]
R2 TryAndDecideService;Acronis Try And Decide Service;"C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe" [2007-09-14 08:12]
S3 CW50;CW50 Device;C:\WINDOWS\system32\DRIVERS\CW50.sys [2001-07-26 21:26]
S3 DCamUSBVeo532;Veo Web Camera;C:\WINDOWS\system32\Drivers\ubVeo532.sys [2002-07-01 18:30]
S3 echogals;Gina20 Service;C:\WINDOWS\system32\drivers\echogals.sys [2003-06-04 14:13]
S3 USB88LDR;Midiman USB MidiSport 8x8/s Loader;C:\WINDOWS\system32\drivers\usb88ldr.sys [2002-04-16 11:21]
S3 USBMIDIM;M-Audio USB MidiSport Midi Kernel Driver;C:\WINDOWS\system32\drivers\usbmidim.sys [2004-08-10 19:09]
S3 USBMM2X4;M-Audio USB MidiSport 2x4 USB Driver;C:\WINDOWS\system32\drivers\usbmm2x4.sys [2004-08-10 19:09]
S3 USBMM8X8;Midiman USB MidiSport 8x8/s Midi Driver;C:\WINDOWS\system32\drivers\usbmm8x8.sys [2002-04-16 11:21]
S4 hpt3xx;hpt3xx;C:\WINDOWS\system32\DRIVERS\hpt3xx.sys [2001-08-17 13:52]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-23 17:11:56 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - JMS44.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-09 07:57:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-09 7:59:25
ComboFix-quarantined-files.txt 2008-01-09 12:58:56
ComboFix2.txt 2008-01-08 03:27:27
ComboFix3.txt 2008-01-07 00:56:03


HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:06:14 AM, on 1/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\WINDOWS\system32\wuauclt.exe
C:\trend micro hijack this\scanner.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [MAFWTaskbarApp] C:\WINDOWS\system32\MAFWTray.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - file://C:\install.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…ol_v1-0-3-9.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093233305013
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155496434812
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - https://brewx.qualcomm.com/noauth/cms/BREW_….0.1/isetup.cab
O16 - DPF: {B2FCED61-570E-11D3-B160-00A0C9E70E84} (OmniForm Form Control) - https://www4.lsac.org/OIFActiveX/ofmctlnew.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

–
End of file - 8697 bytes


Thanks!
Hi

The developer of ComboFix has updated it and given me some new advice, so we're going to run one more CFScript (its being a bit stubborn…).

Please delete your existing copy of ComboFix.exe.

Download a fresh copy from here:
ComboFix.exe

**Save it to your desktop**


1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

RenV::
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor .exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp .exe
C:\Program Files\Common Files\Symantec Shared\ccApp .exe
C:\Program Files\Dell\Support\Alert\bin\DAMon .exe
C:\Program Files\Messenger\msmsgs .exe
C:\Program Files\QuickTime\qttask		  .exe
C:\Program Files\QuickTime\qttask		 .exe
C:\Program Files\QuickTime\qttask		.exe
C:\Program Files\QuickTime\qttask	   .exe
C:\Program Files\QuickTime\qttask	  .exe
C:\Program Files\QuickTime\qttask	 .exe
C:\Program Files\QuickTime\qttask	.exe
C:\Program Files\QuickTime\qttask   .exe
C:\Program Files\QuickTime\qttask  .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD .exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2 .exe
C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\MSConfig .exe
C:\WINDOWS\SYSTEM32\ctfmon .exe
C:\WINDOWS\SYSTEM32\MAFWTray .exe

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Please describe how your computer is running at the moment.

Thanks,

jpshortstuff
hi. This time combofix did reboot my machine. After the last combofix run, my audio control drivers had disappeared from the tray. i figured it removed it as a precaution and i'd have to reinstall it, but now they are back. The machine still seems a bit slower on the boot (hanging on the desktop image before icons appear) than before infection but this could just be my imagination…dunno.

here is the combofix log:

ComboFix 08-01-10.2 - jms44 2008-01-10 8:53:58.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.207 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\jms44\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-12-10 to 2008-01-10 )))))))))))))))))))))))))))))))
.

2008-01-06 19:38 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-02 23:49 . 2008-01-02 23:49 d——– C:\Documents and Settings\All Users\Application Data\ESET
2008-01-01 16:45 . 2007-05-29 13:55 22,112 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.sys
2008-01-01 16:45 . 2007-05-29 13:55 10,592 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.cat
2008-01-01 16:45 . 2007-05-29 13:55 705 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.inf
2007-12-24 13:30 . 2007-12-24 13:30 15,360 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\ctfmon.exe
2007-12-24 13:30 . 2007-12-24 13:30 15,360 –a—— C:\WINDOWS\SYSTEM32\ctfmon.exe
2007-12-23 23:29 . 2008-01-09 08:05 d——– C:\trend micro hijack this
2007-12-23 22:06 . 2007-12-23 22:06 d——– C:\Program Files\Lavasoft
2007-12-23 22:06 . 2007-12-23 22:06 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-23 22:04 . 2007-12-23 22:05 21,216,112 –a—— C:\aaw2007.exe
2007-12-23 12:14 . 2007-12-23 12:20 10,740 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.CAT
2007-12-23 12:14 . 2007-12-23 12:20 805 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.INF
2007-12-23 11:57 . 2007-12-24 13:29 158,208 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\msconfig.exe
2007-12-23 11:57 . 2007-12-31 21:19 155,648 –a—— C:\WINDOWS\SYSTEM32\MAFWTray.exe
2007-12-22 10:36 . 2007-12-22 11:02 d——– C:\surf vids
2007-12-13 21:23 . 2007-12-13 21:23 173,286 –a—— C:\kitchenaide.gif
2007-12-10 21:49 . 2007-12-10 21:50 13,413,048 –a—— C:\Google_Earth_BZXD.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-10 14:00 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-10 13:53 ——— d—–w C:\Program Files\QuickTime
2008-01-04 03:15 ——— d—–w C:\Program Files\Norton AntiVirus
2008-01-01 21:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-24 03:05 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-23 17:20 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-23 17:20 ——— d—–w C:\Program Files\Symantec
2007-12-14 02:22 ——— d—–w C:\Documents and Settings\jms44\Application Data\Canon
2007-12-11 02:51 ——— d—–w C:\Program Files\Google
2007-12-01 04:57 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-12-01 04:57 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-12-01 04:57 279,088 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-12-01 04:57 10,545 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-12-01 04:57 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-12-01 04:57 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-12-01 04:57 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-27 02:39 ——— d—–w C:\Program Files\Netflix
2007-11-27 02:18 ——— d—–w C:\Documents and Settings\jms44\Application Data\dvdcss
2007-10-20 19:42 3,024,669 —-a-w C:\cwRsync_2.0.10_Installer.zip
2007-10-20 16:12 143,308,512 —-a-w C:\TrueImage11_d_en.exe
2006-11-25 23:23 71,600 —-a-w C:\Documents and Settings\jms44\Application Data\GDIPFONTCACHEV1.DAT
2004-07-14 20:06 609 —-a-w C:\Program Files\Common Files\alert.vbs
2003-05-21 17:31 951 —-a-w C:\Program Files\INSTALL.LOG
2002-09-14 21:52 779,276,400 —-a-w C:\Documents and Settings\jms44\ambient 1.bin
2002-09-14 21:49 776,025,936 —-a-w C:\Documents and Settings\jms44\bill laswell.bin
2002-09-14 21:39 598,005,408 —-a-w C:\Documents and Settings\jms44\dopeheadz drums.bin
2002-09-14 21:35 706,315,008 —-a-w C:\Documents and Settings\jms44\primitive instruments.bin
2001-05-10 14:04 162,304 —-a-w C:\Program Files\UNWISE.EXE
.
—-a-w		 2,595,480 2008-01-01 02:19:42  C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor .exe


((((((((((((((((((((((((((((( snapshot@2008-01-06_19.55.31.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2000-08-31 13:00:00 163,328 —-a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2008-01-10 13:53:18 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-10 13:53:18 12,288 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-10 13:53:18 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-10 13:53:18 12,288 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-10 13:53:18 6,934,528 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-10 13:53:18 45,056 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
- 2004-08-04 07:56:53 158,208 —-a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\msconfig.exe
+ 2007-12-24 18:29:23 158,208 —-a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\MSConfig.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2007-12-31 21:20 1694208]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\Money Express.exe" [ ]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-12-24 13:30 15360]
"NvMediaCenter"="C:\WINDOWS\system32\NVMCTRAY.DLL" [2003-07-28 14:19 49152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2007-12-31 21:19 679936]
"Dell|Alert"="C:\Program Files\Dell\Support\Alert\bin\DAMon.exe" [2007-12-31 21:19 270336]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 14:19 4841472]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2007-12-31 21:19 49152]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"MAFWTaskbarApp"="C:\WINDOWS\system32\MAFWTray.exe" [2007-12-31 21:19 155648]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2007-12-24 13:29 158208]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [ ]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-12-31 21:19 905056]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-12-31 21:19 140568]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 14:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 14:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"nwiz"="nwiz.exe" [2003-07-28 14:19 323584 C:\WINDOWS\SYSTEM32\nwiz.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-12-31 21:20 84640]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2008-01-03 22:29 26248]

C:\Documents and Settings\jms44\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe [2006-05-23 16:17:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-02-24 18:59:00]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-10-20 22:17:28]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"SpecifyDefaultButtons"= 1 (0x1)
"Btn_Search"= 2 (0x2)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
–a—— 2002-08-03 00:34 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2005-09-20 07:25 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ekrn"=2 (0x2)
"EhttpSrv"=3 (0x3)

R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2007-10-20 11:18]
R1 Asapi;Asapi;C:\WINDOWS\system32\drivers\Asapi.sys [2000-01-08 08:22]
R2 TryAndDecideService;Acronis Try And Decide Service;"C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe" [2007-09-14 08:12]
S3 CW50;CW50 Device;C:\WINDOWS\system32\DRIVERS\CW50.sys [2001-07-26 21:26]
S3 DCamUSBVeo532;Veo Web Camera;C:\WINDOWS\system32\Drivers\ubVeo532.sys [2002-07-01 18:30]
S3 echogals;Gina20 Service;C:\WINDOWS\system32\drivers\echogals.sys [2003-06-04 14:13]
S3 USB88LDR;Midiman USB MidiSport 8x8/s Loader;C:\WINDOWS\system32\drivers\usb88ldr.sys [2002-04-16 11:21]
S3 USBMIDIM;M-Audio USB MidiSport Midi Kernel Driver;C:\WINDOWS\system32\drivers\usbmidim.sys [2004-08-10 19:09]
S3 USBMM2X4;M-Audio USB MidiSport 2x4 USB Driver;C:\WINDOWS\system32\drivers\usbmm2x4.sys [2004-08-10 19:09]
S3 USBMM8X8;Midiman USB MidiSport 8x8/s Midi Driver;C:\WINDOWS\system32\drivers\usbmm8x8.sys [2002-04-16 11:21]
S4 hpt3xx;hpt3xx;C:\WINDOWS\system32\DRIVERS\hpt3xx.sys [2001-08-17 13:52]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-23 17:11:56 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - jms44.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-10 09:01:31
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-10 9:09:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-10 14:09:24
ComboFix2.txt 2008-01-09 12:59:26
ComboFix3.txt 2008-01-08 03:27:27
ComboFix4.txt 2008-01-07 00:56:03


and here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:14:44 AM, on 1/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\WINDOWS\system32\MAFWTray.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\trend micro hijack this\scanner.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [MAFWTaskbarApp] C:\WINDOWS\system32\MAFWTray.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - file://C:\install.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…ol_v1-0-3-9.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093233305013
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155496434812
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - https://brewx.qualcomm.com/noauth/cms/BREW_….0.1/isetup.cab
O16 - DPF: {B2FCED61-570E-11D3-B160-00A0C9E70E84} (OmniForm Form Control) - https://www4.lsac.org/OIFActiveX/ofmctlnew.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

–
End of file - 8995 bytes

Thanks!
Hi

Looks like we killed it, just one more CFScript to clean up.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

RenV::
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor .exe
3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Please do an online scan with Kaspersky WebScanner

Follow this link in Internet Explorer (Note: You must use Internet explorer to use Kaspersky): Kaspersky WebScanner

You will be prompted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    o Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)

    o Scan Options:
    Scan Archives Scan Mail Bases

  • Click OK
  • Now under select a target to scan:
    Select My Computer
  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    o Now click on the Save as Text button:
  • Save the file to your desktop.

Please post the results of the Kaspersky scan in your next reply, along with a fresh HijackThis log.

How is it running now?

Thanks,

jpshortstuff
hey. ComboFix did not require a reboot this time. I didnt see a webscanner on the kaspersky site, but i downloaded their SOS program and ran that. A bunch of stuff came up in system restore points, Norton quarantined items, and some junk emails i never opened. Looks like there were a couple of virues/adware in a few other files that Norton never found. Should i just have kaspersky delete everything it found?

here is the combofix log:

ComboFix 08-01-10.2 - JMS44 2008-01-10 22:00:53.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.179 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\JMS44\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-12-11 to 2008-01-11 )))))))))))))))))))))))))))))))
.

2008-01-06 19:38 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-02 23:49 . 2008-01-02 23:49 d——– C:\Documents and Settings\All Users\Application Data\ESET
2008-01-01 16:45 . 2007-05-29 13:55 22,112 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.sys
2008-01-01 16:45 . 2007-05-29 13:55 10,592 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.cat
2008-01-01 16:45 . 2007-05-29 13:55 705 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.inf
2007-12-24 13:30 . 2007-12-24 13:30 15,360 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\ctfmon.exe
2007-12-24 13:30 . 2007-12-24 13:30 15,360 –a—— C:\WINDOWS\SYSTEM32\ctfmon.exe
2007-12-23 23:29 . 2008-01-10 09:14 d——– C:\trend micro hijack this
2007-12-23 22:06 . 2007-12-23 22:06 d——– C:\Program Files\Lavasoft
2007-12-23 22:06 . 2007-12-23 22:06 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-23 22:04 . 2007-12-23 22:05 21,216,112 –a—— C:\aaw2007.exe
2007-12-23 12:14 . 2007-12-23 12:20 10,740 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.CAT
2007-12-23 12:14 . 2007-12-23 12:20 805 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.INF
2007-12-23 11:57 . 2007-12-24 13:29 158,208 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\msconfig.exe
2007-12-23 11:57 . 2007-12-31 21:19 155,648 –a—— C:\WINDOWS\SYSTEM32\MAFWTray.exe
2007-12-22 10:36 . 2007-12-22 11:02 d——– C:\surf vids
2007-12-13 21:23 . 2007-12-13 21:23 173,286 –a—— C:\kitchenaide.gif

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-10 14:00 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-10 13:53 ——— d—–w C:\Program Files\QuickTime
2008-01-04 03:15 ——— d—–w C:\Program Files\Norton AntiVirus
2008-01-01 21:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-24 18:29 158,208 —-a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\MSConfig.exe
2007-12-24 03:05 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-23 17:20 60,800 —-a-w C:\WINDOWS\SYSTEM32\S32EVNT1.DLL
2007-12-23 17:20 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-23 17:20 ——— d—–w C:\Program Files\Symantec
2007-12-14 02:22 ——— d—–w C:\Documents and Settings\JMS44\Application Data\Canon
2007-12-11 02:51 ——— d—–w C:\Program Files\Google
2007-12-11 02:50 13,413,048 —-a-w C:\Google_Earth_BZXD.exe
2007-12-01 04:57 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-12-01 04:57 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-12-01 04:57 279,088 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-12-01 04:57 10,545 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-12-01 04:57 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-12-01 04:57 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-12-01 04:57 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-27 02:39 ——— d—–w C:\Program Files\Netflix
2007-11-27 02:18 ——— d—–w C:\Documents and Settings\JMS44\Application Data\dvdcss
2007-10-31 00:55 625,032 —-a-w C:\WINDOWS\SYSTEM32\SymNeti.dll
2007-10-31 00:55 242,056 —-a-w C:\WINDOWS\SYSTEM32\SymRedir.dll
2007-10-20 19:42 3,024,669 —-a-w C:\cwRsync_2.0.10_Installer.zip
2007-10-20 16:37 1,880,856 —-a-w C:\WINDOWS\SYSTEM32\AutoPartNt.exe
2007-10-20 16:12 143,308,512 —-a-w C:\TrueImage11_d_en.exe
2006-11-25 23:23 71,600 —-a-w C:\Documents and Settings\JMS44\Application Data\GDIPFONTCACHEV1.DAT
2004-07-14 20:06 609 —-a-w C:\Program Files\Common Files\alert.vbs
2003-05-21 17:31 951 —-a-w C:\Program Files\INSTALL.LOG
2002-09-14 21:52 779,276,400 —-a-w C:\Documents and Settings\JMS44\ambient 1.bin
2002-09-14 21:49 776,025,936 —-a-w C:\Documents and Settings\JMS44\bill laswell.bin
2002-09-14 21:39 598,005,408 —-a-w C:\Documents and Settings\JMS44\dopeheadz drums.bin
2002-09-14 21:35 706,315,008 —-a-w C:\Documents and Settings\JMS44\primitive instruments.bin
2001-05-10 14:04 162,304 —-a-w C:\Program Files\UNWISE.EXE
.

((((((((((((((((((((((((((((( snapshot@2008-01-06_19.55.31.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2000-08-31 13:00:00 163,328 —-a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2008-01-11 03:00:27 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-11 03:00:27 12,288 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-11 03:00:27 237,568 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-11 03:00:27 12,288 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-11 03:00:28 6,934,528 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-11 03:00:28 45,056 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2007-12-31 21:20 1694208]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\Money Express.exe" [ ]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-12-24 13:30 15360]
"NvMediaCenter"="C:\WINDOWS\system32\NVMCTRAY.DLL" [2003-07-28 14:19 49152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2007-12-31 21:19 679936]
"Dell|Alert"="C:\Program Files\Dell\Support\Alert\bin\DAMon.exe" [2007-12-31 21:19 270336]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 14:19 4841472]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2007-12-31 21:19 49152]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"MAFWTaskbarApp"="C:\WINDOWS\system32\MAFWTray.exe" [2007-12-31 21:19 155648]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2007-12-24 13:29 158208]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-12-31 21:19 2595480]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-12-31 21:19 905056]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-12-31 21:19 140568]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 14:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 14:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"nwiz"="nwiz.exe" [2003-07-28 14:19 323584 C:\WINDOWS\SYSTEM32\nwiz.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-12-31 21:20 84640]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2008-01-03 22:29 26248]

C:\Documents and Settings\JMS44\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe [2006-05-23 16:17:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-02-24 18:59:00]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-10-20 22:17:28]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"SpecifyDefaultButtons"= 1 (0x1)
"Btn_Search"= 2 (0x2)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
–a—— 2002-08-03 00:34 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2005-09-20 07:25 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ekrn"=2 (0x2)
"EhttpSrv"=3 (0x3)

R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2007-10-20 11:18]
R1 Asapi;Asapi;C:\WINDOWS\system32\drivers\Asapi.sys [2000-01-08 08:22]
R2 TryAndDecideService;Acronis Try And Decide Service;"C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe" [2007-09-14 08:12]
S3 CW50;CW50 Device;C:\WINDOWS\system32\DRIVERS\CW50.sys [2001-07-26 21:26]
S3 DCamUSBVeo532;Veo Web Camera;C:\WINDOWS\system32\Drivers\ubVeo532.sys [2002-07-01 18:30]
S3 echogals;Gina20 Service;C:\WINDOWS\system32\drivers\echogals.sys [2003-06-04 14:13]
S3 USB88LDR;Midiman USB MidiSport 8x8/s Loader;C:\WINDOWS\system32\drivers\usb88ldr.sys [2002-04-16 11:21]
S3 USBMIDIM;M-Audio USB MidiSport Midi Kernel Driver;C:\WINDOWS\system32\drivers\usbmidim.sys [2004-08-10 19:09]
S3 USBMM2X4;M-Audio USB MidiSport 2x4 USB Driver;C:\WINDOWS\system32\drivers\usbmm2x4.sys [2004-08-10 19:09]
S3 USBMM8X8;Midiman USB MidiSport 8x8/s Midi Driver;C:\WINDOWS\system32\drivers\usbmm8x8.sys [2002-04-16 11:21]
S4 hpt3xx;hpt3xx;C:\WINDOWS\system32\DRIVERS\hpt3xx.sys [2001-08-17 13:52]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-23 17:11:56 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - JMS44.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-10 22:05:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-10 22:07:39
ComboFix-quarantined-files.txt 2008-01-11 03:07:02
ComboFix2.txt 2008-01-10 14:09:33
ComboFix3.txt 2008-01-09 12:59:26
ComboFix4.txt 2008-01-08 03:27:27
ComboFix5.txt 2008-01-07 00:56:03


here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:13:40 PM, on 1/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\WINDOWS\system32\MAFWTray.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\EditPlus 2\editplus.exe
C:\trend micro hijack this\scanner.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [MAFWTaskbarApp] C:\WINDOWS\system32\MAFWTray.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - file://C:\install.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…ol_v1-0-3-9.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093233305013
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155496434812
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - https://brewx.qualcomm.com/noauth/cms/BREW_….0.1/isetup.cab
O16 - DPF: {B2FCED61-570E-11D3-B160-00A0C9E70E84} (OmniForm Form Control) - https://www4.lsac.org/OIFActiveX/ofmctlnew.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

–
End of file - 9099 bytes

here is the kaspersky log:

99% - Scan My Computer
———————-
Scanned: 481394
Detected: 235
Untreated: 235
Start time: 1/10/2008 10:34:04 PM
Duration: 09:39:49
Finish time: Unknown
Signatures published: 1/10/2008 7:30:10 PM


Detected
——–
Status Object
—— ——
detected: adware not-a-virus:AdWare.Win32.Virtumonde.clz File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1194\A0099392.dll
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097083.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097289.rbf
detected: Trojan program Trojan-Downloader.Win32.Osel.bx File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097365.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097378.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097382.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097383.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097384.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097385.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097386.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097387.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097388.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097389.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097393.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097395.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097398.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097402.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097403.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097536.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097539.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097540.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097542.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097543.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097544.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097546.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097548.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097549.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097550.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097552.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097578.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097581.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097582.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097583.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097584.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097585.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097586.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097588.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097590.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097591.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097592.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097594.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097622.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097625.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097626.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097627.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097628.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097629.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097630.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097632.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097634.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097635.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097636.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097638.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097663.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097666.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097667.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097668.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097669.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097670.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097671.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097673.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097675.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097676.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097677.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097681.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097686.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097707.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097709.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097710.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097711.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097712.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097713.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097714.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097716.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097718.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097719.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097720.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097722.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097723.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097724.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097776.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097777.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097778.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097779.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097780.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097781.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097782.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097783.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097784.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097785.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097786.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097787.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097788.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097789.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097791.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097792.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097793.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097801.exe
detected: adware not-a-virus:AdWare.Win32.Agent.vv File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1234\A0097814.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100185.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100188.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100189.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100190.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100191.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100192.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100194.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100196.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100197.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100198.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100200.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100220.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100223.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100224.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100225.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100226.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100227.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100229.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100231.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100232.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100233.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100235.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100241.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100261.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100264.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100265.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100266.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100267.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100268.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100270.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100272.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100273.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100274.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100275.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100276.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100277.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100283.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100284.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100285.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100286.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100287.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100288.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100289.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100290.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100291.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100292.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100293.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100294.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100295.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100296.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100297.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0100309.exe
detected: Trojan program Trojan-Downloader.Win32.Adload.ni File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102322.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102335.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102336.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102337.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102338.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102339.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102340.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102341.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102342.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102343.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102344.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102345.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102346.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102352.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102354.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102355.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102356.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102357.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102358.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102359.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102360.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102361.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102362.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102363.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102364.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102367.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102368.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102389.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102391.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102392.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102393.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102394.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102410.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102411.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102412.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102413.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1235\A0102414.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1237\A0103469.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1237\A0103470.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1237\A0103471.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1237\A0103474.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.cli File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1237\A0103475.exe
detected: virus Email-Worm.Win32.Sobig.f Email message attachment: Outlook\Archive Folders\Top of Personal Folders\Deleted Items\[From:[removed]][Subject:R
e: That movie][Time:2003/08/19 07:03:49]/movie0045.pif
detected: virus Email-Worm.Win32.Bagle.j Email message attachment: Outlook\Archive Folders\Top of Personal Folders\Deleted Items\[From:[removed]][Subject:**JUNK** E-mail account security warning.][Time:2004/03/03 11:50:13]/Information.zip/klusn.exe//UPX
detected: malware Exploit.HTML.Iframe.FileDownload (modification) Email message body: Outlook\Archive Folders\Top of Personal Folders\Deleted Items\[From:itsimazing][Subject:Re:jaredshapiro,please try again][Time:2002/08/07 00:12:19]/RichBody//Html2Rtf
detected: virus Email-Worm.Win32.Bagle.y Email message attachment: Outlook\Archive Folders\Top of Personal Folders\Deleted Items\[From:[removed]][Subject:I just need a friend][Time:2004/04/29 21:59:51]/Info.vbs
detected: virus Email-Worm.Win32.Bagle.y Email message attachment: Outlook\Archive Folders\Top of Personal Folders\Deleted Items\[From:[removed]][Subject:I like you][Time:2004/04/26 23:02:10]/Document.scr
detected: virus Email-Worm.Win32.Mydoom.m Email message attachment: Outlook\Personal Folders\Top of Personal Folders\Inbox\[From:Mail Delivery Subsystem][Subject:Mail System Error - Returned Mail][Time:2004/09/09 20:03:23]/transcript.zip/transcript.exe
detected: malware Exploit.HTML.Iframe.FileDownload (modification) Email message body: Main Identity\Local Folders\Inbox\[From:"itsimazing" <[removed]>][Subject:Re:jaredshapiro,please try again][Time:2002/08/07 00:16:19]/text/html
detected: virus Email-Worm.Win32.Sobig.f Email message attachment: Main Identity\Local Folders\Deleted Items\[From:<[removed]>][Subject:Re: That movie][Time:2003/08/19 11:02:57]/movie0045.pif
detected: Trojan program Trojan-Dropper.Win32.Agent.dmj File: C:\arcade\nes\fceu-0.98.12.win.zip/fceu.exe
detected: Trojan program Trojan-Dropper.Win32.Agent.dmj File: C:\arcade\nes\fceu\fceu.exe
detected: Trojan program Trojan-Downloader.Java.Agent.f File: C:\Documents and Settings\JMS44\.jpi_cache\jar\1.0\jvmsecman.jar-69ee0e0e-36760122.zip/vlocal.class
detected: virus Email-Worm.Win32.Mimail.j File: C:\Program Files\Norton AntiVirus\Quarantine\1B6D17F8.tmp//CryptFF
detected: virus Email-Worm.Win32.Mimail.j File: C:\Program Files\Norton AntiVirus\Quarantine\1BBB07A2.tmp//CryptFF
detected: virus Email-Worm.Win32.Mimail.j File: C:\Program Files\Norton AntiVirus\Quarantine\1BCB5990.tmp//CryptFF
detected: virus Email-Worm.Win32.Mimail.j File: C:\Program Files\Norton AntiVirus\Quarantine\1BD55785.tmp//CryptFF
detected: virus Email-Worm.Win32.Mimail.j File: C:\Program Files\Norton AntiVirus\Quarantine\1BDF557A.tmp//CryptFF
detected: virus Email-Worm.Win32.Mimail.j File: C:\Program Files\Norton AntiVirus\Quarantine\1BE9536F.tmp//CryptFF
detected: virus Email-Worm.Win32.Mimail.j File: C:\Program Files\Norton AntiVirus\Quarantine\1BF35165.tmp//CryptFF
detected: virus Email-Worm.Win32.Mimail.j File: C:\Program Files\Norton AntiVirus\Quarantine\1BFC4F5A.tmp//CryptFF
detected: virus Email-Worm.Win32.Mimail.j File: C:\Program Files\Norton AntiVirus\Quarantine\1C064D4F.tmp//CryptFF
detected: virus Email-Worm.Win32.Mimail.j File: C:\Program Files\Norton AntiVirus\Quarantine\32EE22AC.tmp//CryptFF
detected: virus Email-Worm.Win32.Mimail.j File: C:\Program Files\Norton AntiVirus\Quarantine\32FE749A.tmp//CryptFF
detected: virus Email-Worm.Win32.Mimail.j File: C:\Program Files\Norton AntiVirus\Quarantine\330B1C8C.tmp//CryptFF
detected: virus Email-Worm.Win32.Mimail.j File: C:\Program Files\Norton AntiVirus\Quarantine\4D674C66.tmp//CryptFF
detected: virus Email-Worm.Win32.Mimail.j File: C:\Program Files\Norton AntiVirus\Quarantine\4D747457.tmp//CryptFF
detected: virus Net-Worm.Win32.Nimda.e File: C:\Program Files\Norton AntiVirus\Quarantine\4E0357DD.exe//CryptFF
detected: adware not-a-virus:AdWare.Win32.ISearch.b File: C:\Program Files\Norton AntiVirus\Quarantine\4F875C31.dll//CryptFF
detected: virus Email-Worm.Win32.Mimail.j File: C:\Program Files\Norton AntiVirus\Quarantine\7D7766EE.tmp//CryptFF
detected: virus Email-Worm.Win32.Mimail.j File: C:\Program Files\Norton AntiVirus\Quarantine\7D8164E4.tmp//CryptFF
detected: malware Exploit.Java.ByteVerify File: C:\Program Files\Norton AntiVirus\Quarantine\7FC91928.zip//CryptFF/BlackBox.class
detected: malware Exploit.Java.ByteVerify File: C:\Program Files\Norton AntiVirus\Quarantine\7FC91928.zip//CryptFF/VerifierBug.class
detected: Trojan program Trojan-Downloader.Java.OpenConnection.aa File: C:\Program Files\Norton AntiVirus\Quarantine\7FC91928.zip//CryptFF/Beyond.class
detected: Trojan program Trojan.Java.ClassLoader.c File: C:\Program Files\Norton AntiVirus\Quarantine\7FDF3F0F.zip//CryptFF/GetAccess.class
detected: malware Exploit.Java.ByteVerify File: C:\Program Files\Norton AntiVirus\Quarantine\7FDF3F0F.zip//CryptFF/InsecureClassLoader.class
detected: Trojan program Trojan.Java.ClassLoader.Dummy.a File: C:\Program Files\Norton AntiVirus\Quarantine\7FDF3F0F.zip//CryptFF/Dummy.class
detected: Trojan program Trojan-Downloader.Java.OpenConnection.v File: C:\Program Files\Norton AntiVirus\Quarantine\7FDF3F0F.zip//CryptFF/Installer.class
detected: malware Exploit.Java.ByteVerify File: C:\Program Files\Norton AntiVirus\Quarantine\7FEC6701.tmp//CryptFF/BlackBox.class
detected: malware Exploit.Java.ByteVerify File: C:\Program Files\Norton AntiVirus\Quarantine\7FEC6701.tmp//CryptFF/VerifierBug.class
detected: Trojan program Trojan-Downloader.Java.OpenConnection.aa File: C:\Program Files\Norton AntiVirus\Quarantine\7FEC6701.tmp//CryptFF/Beyond.class
detected: adware not-a-virus:AdWare.Win32.Gator.3202 File: C:\Program Files\Rippackv3\Logiciels\codec\DivX5.02\DivXPro502GAINBundle.exe//Gain_Trickler.exe
detected: Trojan program Trojan-Dropper.Win32.Agent.dmj File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1249\A0105034.exe
detected: adware not-a-virus:AdWare.Win32.Gator.3202 File: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1249\A0105035.exe//Gain_Trickler.exe


Events
——
Time Name Status Reason
—- —- —— ——
1/10/2008 10:34:04 PM Running module: smss.exe\smss.exe ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\System32\smss.exe ok iSwift
1/10/2008 10:34:04 PM Running module: smss.exe\ntdll.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\ntdll.dll ok iSwift
1/10/2008 10:34:04 PM Running module: csrss.exe\csrss.exe ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\csrss.exe ok iSwift
1/10/2008 10:34:04 PM Running module: csrss.exe\ntdll.dll ok iChecker
1/10/2008 10:34:04 PM Running module: csrss.exe\CSRSRV.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\CSRSRV.dll ok iSwift
1/10/2008 10:34:04 PM Running module: csrss.exe\basesrv.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\basesrv.dll ok iSwift
1/10/2008 10:34:04 PM Running module: csrss.exe\winsrv.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\winsrv.dll ok iSwift
1/10/2008 10:34:04 PM Running module: csrss.exe\GDI32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\GDI32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: csrss.exe\KERNEL32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\KERNEL32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: csrss.exe\USER32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\USER32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: csrss.exe\sxs.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\sxs.dll ok iSwift
1/10/2008 10:34:04 PM Running module: csrss.exe\ADVAPI32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\ADVAPI32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: csrss.exe\RPCRT4.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\RPCRT4.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\winlogon.exe ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\winlogon.exe ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\ntdll.dll ok iChecker
1/10/2008 10:34:04 PM Running module: winlogon.exe\kernel32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\kernel32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\ADVAPI32.dll ok iChecker
1/10/2008 10:34:04 PM Running module: winlogon.exe\RPCRT4.dll ok iChecker
1/10/2008 10:34:04 PM Running module: winlogon.exe\AUTHZ.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\AUTHZ.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\msvcrt.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\msvcrt.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\CRYPT32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\CRYPT32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\USER32.dll ok iChecker
1/10/2008 10:34:04 PM Running module: winlogon.exe\GDI32.dll ok iChecker
1/10/2008 10:34:04 PM Running module: winlogon.exe\MSASN1.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\MSASN1.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\NDdeApi.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\NDdeApi.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\PROFMAP.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\PROFMAP.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\NETAPI32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\NETAPI32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\USERENV.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\USERENV.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\PSAPI.DLL ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\PSAPI.DLL ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\REGAPI.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\REGAPI.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\Secur32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\Secur32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\SETUPAPI.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\SETUPAPI.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\VERSION.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\VERSION.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\WINSTA.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\WINSTA.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\WINTRUST.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\WINTRUST.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\IMAGEHLP.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\IMAGEHLP.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\WS2_32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\WS2_32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\WS2HELP.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\WS2HELP.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\IMM32.DLL ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\IMM32.DLL ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\MSGINA.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\MSGINA.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\SHELL32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\SHELL32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\SHLWAPI.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\SHLWAPI.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\COMCTL32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\COMCTL32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\ODBC32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\ODBC32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\comdlg32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\comdlg32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\comctl32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\odbcint.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\odbcint.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\SHSVCS.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\SHSVCS.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\sfc.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\sfc.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\sfc_os.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\sfc_os.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\ole32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\ole32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\Apphelp.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\Apphelp.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\msctfime.ime ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\msctfime.ime ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\awgina.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\System32\awgina.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\uxtheme.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\uxtheme.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\cscdll.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\cscdll.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\WlNotify.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\WlNotify.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\WINMM.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\WINMM.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\WinSCard.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\WinSCard.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\WTSAPI32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\WTSAPI32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\WINSPOOL.DRV ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\WINSPOOL.DRV ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\MPR.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\MPR.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\serwvdrv.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\serwvdrv.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\umdmxfrm.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\umdmxfrm.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\rsaenh.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\rsaenh.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\WgaLogon.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\WgaLogon.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\OLEAUT32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\OLEAUT32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\NTMARTA.DLL ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\NTMARTA.DLL ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\WLDAP32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\WLDAP32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\SAMLIB.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\SAMLIB.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\CLBCATQ.DLL ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\CLBCATQ.DLL ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\COMRes.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\COMRes.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\sxs.dll ok iChecker
1/10/2008 10:34:04 PM Running module: winlogon.exe\msv1_0.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\msv1_0.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\iphlpapi.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\iphlpapi.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\RASAPI32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\RASAPI32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\rasman.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\rasman.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\TAPI32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\TAPI32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\rtutils.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\rtutils.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\cscui.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\cscui.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\xpsp2res.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\xpsp2res.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\wdmaud.drv ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\wdmaud.drv ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\msacm32.drv ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\msacm32.drv ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\MSACM32.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\MSACM32.dll ok iSwift
1/10/2008 10:34:04 PM Running module: winlogon.exe\midimap.dll ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\midimap.dll ok iSwift
1/10/2008 10:34:04 PM Running module: services.exe\services.exe ok iChecker
1/10/2008 10:34:04 PM File: C:\WINDOWS\system32\services.exe ok iSwift
1/10/2008 10:34:04 PM Running module: services.exe\ntdll.dll ok iChecker
1/10/2008 10:34:04 PM Running module: services.exe\kernel32.dll ok iChecker
1/10/2008 10:34:04 PM Running module: services.exe\msvcrt.dll ok iChecker
1/10/2008 10:34:04 PM Running module: services.exe\ADVAPI32.dll ok iChecker
1/10/2008 10:34:04 PM Running module: services.exe\RPCRT4.dll ok iChecker
1/10/2008 10:34:04 PM Running module: services.exe\USER32.dll ok iChecker
1/10/2008 10:34:04 PM Running module: services.exe\GDI32.dll ok iChecker
1/10/2008 10:34:04 PM Running module: services.exe\USERENV.dll ok iChecker
1/10/2008 10:34:04 PM Running module: services.exe\SCESRV.dll ok iChecker


Statistics
———-
Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
—— ——- ——– ——— ——- ——————- ——– ———— —————— ———


Settings
——–
Parameter Value
——— —–
Security Level Recommended
Action Prompt for action when the scan is complete
Run mode Manually
File types Scan all files
Scan only new and changed files No
Scan archives All
Scan embedded OLE objects All
Skip if object is larger than No
Skip if scan takes longer than No
Parse email formats No
Scan password-protected archives No
Enable iChecker technology Yes
Enable iSwift technology Yes
Record information about dangerous objects to program statistics Yes


thanks!
Hi


Due to reasons outlined here, I recommend you uninstall:
DivX 5.0.2/3 Pro Bundle
By going to Start >> Control Panel >> Add/Remove Programs.

Follow instructions from this link to clean the contents of your Symantec Quarantine folder.


Find and delete the following folder:
C:\arcade\nes\fceu << FOLDER


Please do this:
  • Copy the contents of the Code Box below to Notepad.
  • Name the file as fix.reg
  • Change the Save as Type to All Files
  • and Save it on the desktop
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe"
Make sure there are NO blank lines before REGEDIT4

Then double-click on the fix.reg file, and when it prompts to merge say yes.


Reboot and post a new HijackThis log.

Hows the computer running?
hi.
so i don't have to worry about any of those things that kaspersky found in \system volume information\_restore ?
i dont notice any changes in how the machine is running. aside from some weirdness the first time i rebooted after running kaspersky and leaving my machine on all day, i havent seen any poor behavior. when i went to restart i got a popup saying that dwwin.exe failed to init because machine is shutting down, and i also got a popup saying it couldn't end the program 'sw'. A quick google search for sw.exe said this might be spyware. cause for concern?

here's the latest HJT log.

Thanks!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:38:56 PM, on 1/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\WINDOWS\system32\MAFWTray.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\WINDOWS\system32\wuauclt.exe
C:\trend micro hijack this\scanner.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [MAFWTaskbarApp] C:\WINDOWS\system32\MAFWTray.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - S-1-5-18 Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe (User 'Default user')
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - file://C:\install.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…ol_v1-0-3-9.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093233305013
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1155496434812
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - https://brewx.qualcomm.com/noauth/cms/BREW_….0.1/isetup.cab
O16 - DPF: {B2FCED61-570E-11D3-B160-00A0C9E70E84} (OmniForm Form Control) - https://www4.lsac.org/OIFActiveX/ofmctlnew.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

–
End of file - 9765 bytes
Hi

Sorry about the delays.


When you ran the Kaspersky scan were you prompted to install anything? There is a Kaspersky engine and Virus Definitions installed on your computer, which may well prevent you from running KAV scans in the future. Please go into Add/Remove Programs and remove all instances of Kaspersky.


Those entries you see in the Kaspersky scan are in the System Restore. We will clean this at then end, but don't worry, the files are not active.


Open HijackThis. Hit Do A System Scan Only. Place a check next to the following items (if present):
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - file://C:\install.cab

Close all browsers and windows except for HijackThis and click Fix Checked.


Close all windows and browsers.
Open HijackThis.

Click on Open Misc Tools
Click on Delete a File On Reboot
Click once on the file below to select it:
C:\install.cab
And then click Open.

When prompted to reboot your computer, click yes.


The infection you had appears to have removed with it some files that are required to run the following programs:
Microsoft Works
Microsoft Money


If it is at all possible, and you use these programs, then I would suggest you uninstall them by clicking Start >> Control Panel >> Add/Remove Programs and then clicking "Remove" by these items. Then install them again from their original source.



Just a few questions about your computer:
  • Is QuickTime running properly?

  • Are you still getting those errors when shutting down?

  • Have you installed all recent Windows updates? If not, please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates.
Logs are looking good, any other problems at the moment?

Thanks,

jpshortstuff

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI