This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Help w/Another Vundo / mljji.dll Infection

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Vundo / mljji.dll Infection. I ran Kaspersky AV with some success. However Vundo not leaving that easily.

Included Logs below:

*VundoFix Log
*ComboFix Log
*hijackthis Log

Thanks for the help.

================================================================================
================================

VundoFix V6.6.2

Checking Java version…

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Scan started at 11:25:05 AM 1/13/2008

Listing files found while scanning….

No infected files were found.


Beginning removal…
================================================================================
===============================================

ComboFix 08-01-13.1 - Courtney Porter 2008-01-13 12:01:40.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.194 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\Courtney Porter\Application Data\CURITY~1
C:\Documents and Settings\Courtney Porter\Application Data\CURITY~1\??curity\
C:\Documents and Settings\Courtney Porter\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Courtney Porter\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Courtney Porter\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt
C:\Program Files\Common Files\drivecleaner free
C:\Program Files\Common Files\icroso~1
C:\Program Files\network monitor
C:\Program Files\network monitor\netmon.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\Temporary
C:\Program Files\Temporary\kernInst.exe
C:\Program Files\web buying
C:\Program Files\web buying\v1.8.6\wbuninst.exe
C:\Program Files\web buying\v1.8.6\webbuying .exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\Downloaded Program Files\UGA6P_0001_N122M2210NetInstaller.exe
C:\WINDOWS\mrofinu.exe.bin
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\ijjlm.ini
C:\WINDOWS\system32\ijjlm.ini2
C:\WINDOWS\system32\MabryObj.dll
C:\WINDOWS\system32\mljji.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\Network Monitor


((((((((((((((((((((((((( Files Created from 2007-12-13 to 2008-01-13 )))))))))))))))))))))))))))))))
.

2008-01-13 12:42 . 2008-01-13 12:42 d——– C:\Temp\tn3
2008-01-13 12:41 . 2008-01-13 12:41 932 ——— C:\WINDOWS\system32\drivers\core.cache.dsk
2008-01-13 12:14 . 2008-01-13 12:42 d——– C:\Documents and Settings\LocalService\Application Data\NetMon
2008-01-13 11:47 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-13 11:42 . 2008-01-13 11:42 d——– C:\Program Files\Trend Micro
2008-01-13 11:21 . 2008-01-13 12:17 329,728 –a—— C:\WINDOWS\system32\mljji.exe
2008-01-13 11:14 . 2007-10-10 17:55 6,065,664 ——— C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-13 11:14 . 2007-06-30 21:31 2,455,488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-13 11:14 . 2007-06-30 21:36 991,232 ——— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-13 11:14 . 2007-10-10 17:55 459,264 ——— C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-13 11:14 . 2007-10-10 17:55 383,488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-13 11:14 . 2007-10-10 17:55 267,776 ——— C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-13 11:14 . 2007-10-10 17:55 63,488 ——— C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-13 11:14 . 2007-10-10 17:55 52,224 ——— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-13 11:14 . 2007-10-10 04:59 13,824 ——— C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-13 11:07 . 2008-01-13 11:13 1,374 –a—— C:\WINDOWS\imsins.BAK
2008-01-13 10:38 . 2008-01-13 10:38 d——– C:\admin
2008-01-13 10:36 . 2008-01-13 10:36 d——– C:\Program Files\CCleaner
2008-01-13 10:24 . 2008-01-13 10:24 2 –a—— C:\WINDOWS\msoffice.ini
2008-01-13 01:31 . 2005-08-19 10:34 d——– C:\Documents and Settings\Administrator\Application Data\Symantec
2008-01-13 01:31 . 2005-08-19 10:29 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-01-13 01:31 . 2005-08-19 10:38 d——– C:\Documents and Settings\Administrator\Application Data\Gtek
2008-01-09 10:32 . 2008-01-09 10:51 91,492 –a—— C:\WINDOWS\system32\drivers\klin.dat
2008-01-09 10:32 . 2008-01-09 10:51 85,860 –a—— C:\WINDOWS\system32\drivers\klick.dat
2008-01-09 10:23 . 2008-01-09 10:23 d——– C:\Program Files\Kaspersky Lab
2008-01-09 10:23 . 2008-01-13 12:42 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-09 10:22 . 2008-01-13 12:42 1,901,344 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-09 10:22 . 2008-01-13 12:17 26,420 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-09 10:22 . 2008-01-13 12:42 24,096 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-09 10:22 . 2008-01-13 12:17 3,308 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-09 10:19 . 2008-01-09 10:19 d——– C:\KAV
2008-01-08 14:03 . 2008-01-13 01:16 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2008-01-08 12:46 . 2008-01-13 01:16 114,688 –a—— C:\WINDOWS\system32\igfxpers .exe
2008-01-08 12:46 . 2008-01-13 01:16 94,208 –a—— C:\WINDOWS\system32\igfxtray .exe
2008-01-08 12:46 . 2008-01-13 01:16 77,824 –a—— C:\WINDOWS\system32\hkcmd .exe
2008-01-08 12:44 . 2008-01-13 01:15 188,416 –a—— C:\WINDOWS\system32\ESDUSBMon .EXE
2008-01-08 12:25 . 2008-01-08 12:25 4,286 –a—— C:\WINDOWS\system32\MobileSidewalk.ico
2008-01-08 12:18 . 2008-01-09 10:41 d——– C:\Program Files\Dot1XCfg
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\usmvt3
2008-01-08 12:14 . 2008-01-08 12:20 d——– C:\WINDOWS\system32\drivez4
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\comp2
2008-01-08 12:14 . 2008-01-08 12:14 d——– C:\WINDOWS\system32\cache3
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\ardCo01
2008-01-08 12:14 . 2008-01-08 12:43 d–hs—- C:\WINDOWS\Q291cnRuZXkgUG9ydGVy
2008-01-08 12:14 . 2008-01-08 12:14 d——– C:\Temp\cEeer12
2008-01-08 12:14 . 2008-01-13 12:42 d——– C:\Temp
2008-01-08 12:14 . 2008-01-08 12:14 86,016 –a—— C:\WINDOWS\system32\drivers\asc35500.sys
2007-12-24 14:42 . 2007-12-24 14:42 d——– C:\Documents and Settings\All Users\Application Data\Dell

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-13 16:26 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-13 16:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-13 16:18 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-13 16:17 ——— d—–w C:\Program Files\Yahoo!
2008-01-13 16:15 ——— d—–w C:\Program Files\The Weather Channel FW
2008-01-13 15:22 ——— d—–w C:\Program Files\Dell Support
2008-01-13 15:18 ——— d—–w C:\Program Files\QuickTime
2008-01-07 21:43 ——— d—–w C:\Program Files\TeleTracker Online
2007-11-16 21:02 ——— d—–w C:\Program Files\Coupons
2007-11-16 16:24 ——— d—–w C:\Documents and Settings\Courtney Porter\Application Data\Zango
2007-11-16 16:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\ZangoSA
2007-11-16 16:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2004-12-21 23:34 25,214 —-a-w C:\Program Files\dplogo32.ico
.
—-a-w		   307,200 2008-01-13 07:16:55  C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe
—-a-w		 1,404,928 2008-01-13 07:16:18  C:\Program Files\Analog Devices\Core\smax4pnp .exe
—-a-w			81,920 2008-01-13 07:16:19  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		   221,184 2008-01-13 07:16:19  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
—-a-w			53,248 2008-01-13 07:16:13  C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
—-a-w		   395,776 2008-01-13 07:16:49  C:\Program Files\Dell Support\DSAgnt .exe
—-a-w			61,440 2008-01-09 16:41:57  C:\Program Files\Dot1XCfg\Dot1XCfg .exe
—-a-w			49,152 2008-01-13 07:16:26  C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2 .exe
—-a-w		   241,664 2008-01-13 07:16:24  C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
—-a-w			32,881 2008-01-13 07:16:13  C:\Program Files\Java\j2re1.4.2_03\bin\jusched .exe
—-a-w		   218,376 2008-01-13 15:23:10  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp   .exe
—-a-w			26,112 2008-01-13 07:16:20  C:\Program Files\Real\RealPlayer\RealPlay .exe
—-a-w			15,360 2008-01-13 07:16:55  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   188,416 2008-01-13 07:15:36  C:\WINDOWS\system32\ESDUSBMon .EXE
—-a-w			77,824 2008-01-13 07:16:30  C:\WINDOWS\system32\hkcmd .exe
—-a-w		   114,688 2008-01-13 07:16:32  C:\WINDOWS\system32\igfxpers .exe
—-a-w			94,208 2008-01-13 07:16:29  C:\WINDOWS\system32\igfxtray .exe
—-a-w		   127,035 2008-01-13 07:16:18  C:\WINDOWS\system32\dla\tfswctrl .exe
—-a-w		   172,032 2008-01-13 07:16:20  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10 .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5A074B21-F830-49de-A31B-40463F552DA4}]
2006-08-10 14:04 237184 –a—— C:\Program Files\MyDailyVideo\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5A074B29-F830-49DE-A31B-40463F552DA4}

[HKEY_CLASSES_ROOT\clsid\{5a074b29-f830-49de-a31b-40463f552da4}]
[HKEY_CLASSES_ROOT\TypeLib\{5A074B20-F830-49de-A31B-40463F552DA4}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{5A074B29-F830-49DE-A31B-40463F552DA4}"= C:\Program Files\MyDailyVideo\bar\bin\askBar.dll [2006-08-10 14:04 237184]

[HKEY_CLASSES_ROOT\clsid\{5a074b29-f830-49de-a31b-40463f552da4}]
[HKEY_CLASSES_ROOT\TypeLib\{5A074B20-F830-49de-A31B-40463F552DA4}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe" [2008-01-13 09:23 218376]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 10:59:36]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 22:44:08]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\Windows Media Player\vilozonil.html
FriendlyName=

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 13:11 233472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyywww]

R1 asc35500;asc35500;C:\WINDOWS\system32\drivers\asc35500.sys [2008-01-08 12:14]
R2 avp ;avp ;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe" [2008-01-13 09:23]
R2 Esdpdx01;Esdpdx01;C:\WINDOWS\system32\Drivers\ESDPDX01.SYS [2003-12-25 11:00]
R2 WinRT;WinRT;C:\WINDOWS\system32\drivers\WinRT.sys [2002-12-30 12:33]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
S3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys []
S3 dpK00701;U.are.U Fingerprint Reader Upper Driver;C:\WINDOWS\system32\DRIVERS\dpK00701.sys [2004-10-12 14:51]
S3 TMUSB;EPSON USB Device Driver for TM/BA/EU Printers;C:\WINDOWS\system32\DRIVERS\TMUSBXP.SYS [2007-01-19 08:07]
S3 UsbdpFP;U.are.U Fingerprint Reader Class Driver;C:\WINDOWS\system32\DRIVERS\UsbdpFP.sys [2004-10-12 14:53]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-13 12:42:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-13 12:46:26 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-13 18:46:20
.
2008-01-13 17:16:15 — E O F —

================================================================================
==========================================

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:51:13 PM, on 1/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\WINDOWS\system32\EpStsSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
C:\Program Files\Windows Desktop Search\WindowsSearchFilter.exe
C:\Program Files\Trend Micro\HijackThis\Killer.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://indirect.nextel.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: askBar BHO - {5A074B21-F830-49de-A31B-40463F552DA4} - C:\Program Files\MyDailyVideo\bar\bin\askBar.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: Ask Toolbar - {5A074B29-F830-49de-A31B-40463F552DA4} - C:\Program Files\MyDailyVideo\bar\bin\askBar.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Save Image to Folder - res://C:\Program Files\MyDailyVideo\bar\bin\askBar.dll/saveimagestofolder.html
O8 - Extra context menu item: &Save Image to MyStuff - res://C:\Program Files\MyDailyVideo\bar\bin\askBar.dll/saveimages.html
O8 - Extra context menu item: &Save Link to Folder - res://C:\Program Files\MyDailyVideo\bar\bin\askBar.dll/saveltof.html
O8 - Extra context menu item: &Save Link to MyStuff - res://C:\Program Files\MyDailyVideo\bar\bin\askBar.dll/savelink.html
O8 - Extra context menu item: &Save Page to Folder… - res://C:\Program Files\MyDailyVideo\bar\bin\askBar.dll/savepagetofolder.html
O8 - Extra context menu item: &Save this Page to MyStuff - res://C:\Program Files\MyDailyVideo\bar\bin\askBar.dll/savewebpage.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://teletracker.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CDDDD661-2028-4607-A3CE-3F50828625BA}: NameServer = 205.152.37.23,205.152.132.23
O20 - Winlogon Notify: xxyywww - C:\WINDOWS\
O23 - Service: avp - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
O23 - Service: Biometric Authentication Service (DpHost) - Digital Persona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHost.exe
O23 - Service: EPSON ESC/POS Status Service (EPSON ESCPOS Status Service) - SEIKO EPSON Corp. - C:\WINDOWS\SYSTEM32\EpStsSrv.exe
O23 - Service: lmab_device - Lexmark International, Inc. - C:\WINDOWS\system32\LMabcoms.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Windows Media Player\vilozonil.html
O24 - Desktop Component 1: (no name) - http://indirect.nextel.com/secured_site/images/header_bg.gif
O24 - Desktop Component 3: (no name) - http://www.fatcow.com/

–
End of file - 6440 bytes
plusco, :)

Welcome to the forum, first let me say that I appreciate you trying to fix this garbage yourself but you can bork your system by running removal programs that you have no knowledge of, please do not run any more scans unless directed or I will not be responsible for your system.

C:\Program Files\MyDailyVideo <– This is getting poor results, why don't you try uninstalling it via the Add Remove Programs in the Control Panel.

The main problem your having is that your infected with a newer variation of Vundo which includes a File Infecter and has infected some of your programs that in turn is reinfecting you over and over again.

Drag Combofix to the Trash and download the latest version , then do this.


Download ComboFix from Here or Here to your Desktop.

Open Notepad and copy all the text inside the quote box by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad

File::
C:\WINDOWS\system32\mljji.exe
C:\WINDOWS\imsins.BAK

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyywww]

RenV::
—-a-w 307,200 2008-01-13 07:16:55 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe
—-a-w 1,404,928 2008-01-13 07:16:18 C:\Program Files\Analog Devices\Core\smax4pnp .exe
—-a-w 81,920 2008-01-13 07:16:19 C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w 221,184 2008-01-13 07:16:19 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
—-a-w 53,248 2008-01-13 07:16:13 C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
—-a-w 395,776 2008-01-13 07:16:49 C:\Program Files\Dell Support\DSAgnt .exe
—-a-w 61,440 2008-01-09 16:41:57 C:\Program Files\Dot1XCfg\Dot1XCfg .exe
—-a-w 49,152 2008-01-13 07:16:26 C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2 .exe
—-a-w 241,664 2008-01-13 07:16:24 C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
—-a-w 32,881 2008-01-13 07:16:13 C:\Program Files\Java\j2re1.4.2_03\bin\jusched .exe
—-a-w 218,376 2008-01-13 15:23:10 C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
—-a-w 26,112 2008-01-13 07:16:20 C:\Program Files\Real\RealPlayer\RealPlay .exe
—-a-w 15,360 2008-01-13 07:16:55 C:\WINDOWS\system32\ctfmon .exe
—-a-w 188,416 2008-01-13 07:15:36 C:\WINDOWS\system32\ESDUSBMon .EXE
—-a-w 77,824 2008-01-13 07:16:30 C:\WINDOWS\system32\hkcmd .exe
—-a-w 114,688 2008-01-13 07:16:32 C:\WINDOWS\system32\igfxpers .exe
—-a-w 94,208 2008-01-13 07:16:29 C:\WINDOWS\system32\igfxtray .exe
—-a-w 127,035 2008-01-13 07:16:18 C:\WINDOWS\system32\dla\tfswctrl .exe
—-a-w 172,032 2008-01-13 07:16:20 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10 .exe


Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.
Thanks for the help…

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:34:13 PM, on 1/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\WINDOWS\system32\EpStsSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\ESDUSBMon.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\Killer.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://indirect.nextel.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://teletracker.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CDDDD661-2028-4607-A3CE-3F50828625BA}: NameServer = 205.152.37.23,205.152.132.23
O23 - Service: avp - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
O23 - Service: Biometric Authentication Service (DpHost) - Digital Persona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHost.exe
O23 - Service: EPSON ESC/POS Status Service (EPSON ESCPOS Status Service) - SEIKO EPSON Corp. - C:\WINDOWS\SYSTEM32\EpStsSrv.exe
O23 - Service: lmab_device - Lexmark International, Inc. - C:\WINDOWS\system32\LMabcoms.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Windows Media Player\vilozonil.html
O24 - Desktop Component 1: (no name) - http://indirect.nextel.com/secured_site/images/header_bg.gif
O24 - Desktop Component 3: (no name) - http://www.fatcow.com/

–
End of file - 5451 bytes
================================================================================
=

ComboFix 08-01-15.3 - Courtney Porter 2008-01-14 19:16:15.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.186 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Courtney Porter\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\imsins.BAK
C:\WINDOWS\system32\mljji.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\LocalService\Application Data\NetMon
C:\temp\tn3
C:\WINDOWS\imsins.BAK
C:\WINDOWS\system32\mljji.exe
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2007-12-15 to 2008-01-15 )))))))))))))))))))))))))))))))
.

2008-01-14 19:26 . 2008-01-14 19:26 d——– C:\Temp\tn3
2008-01-14 19:25 . 2008-01-14 19:25 932 ——— C:\WINDOWS\system32\drivers\core.cache.dsk
2008-01-13 11:47 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-13 11:42 . 2008-01-13 11:42 d——– C:\Program Files\Trend Micro
2008-01-13 11:14 . 2007-10-10 17:55 6,065,664 ——— C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-13 11:14 . 2007-06-30 21:31 2,455,488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-13 11:14 . 2007-06-30 21:36 991,232 ——— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-13 11:14 . 2007-10-10 17:55 459,264 ——— C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-13 11:14 . 2007-10-10 17:55 383,488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-13 11:14 . 2007-10-10 17:55 267,776 ——— C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-13 11:14 . 2007-10-10 17:55 63,488 ——— C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-13 11:14 . 2007-10-10 17:55 52,224 ——— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-13 11:14 . 2007-10-10 04:59 13,824 ——— C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-13 10:38 . 2008-01-13 10:38 d——– C:\admin
2008-01-13 10:36 . 2008-01-13 10:36 d——– C:\Program Files\CCleaner
2008-01-13 10:24 . 2008-01-13 10:24 2 –a—— C:\WINDOWS\msoffice.ini
2008-01-13 01:31 . 2005-08-19 10:34 d——– C:\Documents and Settings\Administrator\Application Data\Symantec
2008-01-13 01:31 . 2005-08-19 10:29 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-01-13 01:31 . 2005-08-19 10:38 d——– C:\Documents and Settings\Administrator\Application Data\Gtek
2008-01-09 10:32 . 2008-01-09 10:51 91,492 –a—— C:\WINDOWS\system32\drivers\klin.dat
2008-01-09 10:32 . 2008-01-09 10:51 85,860 –a—— C:\WINDOWS\system32\drivers\klick.dat
2008-01-09 10:23 . 2008-01-09 10:23 d——– C:\Program Files\Kaspersky Lab
2008-01-09 10:23 . 2008-01-14 19:26 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-09 10:22 . 2008-01-14 19:27 2,053,664 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-09 10:22 . 2008-01-14 19:25 29,728 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-09 10:22 . 2008-01-14 19:25 28,388 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-09 10:22 . 2008-01-14 19:25 3,836 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-09 10:19 . 2008-01-09 10:19 d——– C:\KAV
2008-01-08 14:03 . 2008-01-13 01:16 15,360 –a—— C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-01-08 14:03 . 2008-01-13 01:16 15,360 –a—— C:\WINDOWS\system32\ctfmon.exe
2008-01-08 12:46 . 2008-01-13 01:16 114,688 –a—— C:\WINDOWS\system32\igfxpers.exe
2008-01-08 12:46 . 2008-01-13 01:16 94,208 –a—— C:\WINDOWS\system32\igfxtray.exe
2008-01-08 12:46 . 2008-01-13 01:16 77,824 –a—— C:\WINDOWS\system32\hkcmd.exe
2008-01-08 12:44 . 2008-01-13 01:15 188,416 –a—— C:\WINDOWS\system32\ESDUSBMon.EXE
2008-01-08 12:25 . 2008-01-08 12:25 4,286 –a—— C:\WINDOWS\system32\MobileSidewalk.ico
2008-01-08 12:18 . 2008-01-14 19:16 d——– C:\Program Files\Dot1XCfg
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\usmvt3
2008-01-08 12:14 . 2008-01-08 12:20 d——– C:\WINDOWS\system32\drivez4
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\comp2
2008-01-08 12:14 . 2008-01-08 12:14 d——– C:\WINDOWS\system32\cache3
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\ardCo01
2008-01-08 12:14 . 2008-01-08 12:43 d–hs—- C:\WINDOWS\Q291cnRuZXkgUG9ydGVy
2008-01-08 12:14 . 2008-01-08 12:14 d——– C:\Temp\cEeer12
2008-01-08 12:14 . 2008-01-14 19:26 d——– C:\Temp
2008-01-08 12:14 . 2008-01-08 12:14 86,016 –a—— C:\WINDOWS\system32\drivers\asc35500.sys
2007-12-24 14:42 . 2007-12-24 14:42 d——– C:\Documents and Settings\All Users\Application Data\Dell

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-15 01:16 ——— d—–w C:\Program Files\Dell Support
2008-01-13 16:26 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-13 16:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-13 16:18 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-13 16:17 ——— d—–w C:\Program Files\Yahoo!
2008-01-13 16:15 ——— d—–w C:\Program Files\The Weather Channel FW
2008-01-13 15:18 ——— d—–w C:\Program Files\QuickTime
2008-01-07 21:43 ——— d—–w C:\Program Files\TeleTracker Online
2007-11-16 21:02 ——— d—–w C:\Program Files\Coupons
2007-11-16 16:24 ——— d—–w C:\Documents and Settings\Courtney Porter\Application Data\Zango
2007-11-16 16:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\ZangoSA
2007-11-16 16:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
2004-12-21 23:34 25,214 —-a-w C:\Program Files\dplogo32.ico
.
—-a-w		   218,376 2008-01-13 15:23:10  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp   .exe


((((((((((((((((((((((((((((( snapshot@2008-01-13_12.45.34.14 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-13 18:00:07 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-15 01:15:16 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-13 18:00:07 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-15 01:15:16 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-13 18:00:07 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-15 01:15:16 4,091,904 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-13 18:00:07 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-15 01:15:16 57,344 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-13 18:00:07 4,091,904 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-15 01:15:16 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-13 18:00:07 57,344 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-15 01:15:16 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-13 07:16:18 127,035 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
+ 2008-01-13 07:16:20 172,032 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-13 01:16 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe" [2008-01-13 09:23 218376]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 10:59:36]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 22:44:08]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\Windows Media Player\vilozonil.html
FriendlyName=

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 13:11 233472]

R1 asc35500;asc35500;C:\WINDOWS\system32\drivers\asc35500.sys [2008-01-08 12:14]
R2 avp ;avp ;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe" [2008-01-13 09:23]
R2 Esdpdx01;Esdpdx01;C:\WINDOWS\system32\Drivers\ESDPDX01.SYS [2003-12-25 11:00]
R2 WinRT;WinRT;C:\WINDOWS\system32\drivers\WinRT.sys [2002-12-30 12:33]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
S3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys []
S3 dpK00701;U.are.U Fingerprint Reader Upper Driver;C:\WINDOWS\system32\DRIVERS\dpK00701.sys [2004-10-12 14:51]
S3 TMUSB;EPSON USB Device Driver for TM/BA/EU Printers;C:\WINDOWS\system32\DRIVERS\TMUSBXP.SYS [2007-01-19 08:07]
S3 UsbdpFP;U.are.U Fingerprint Reader Class Driver;C:\WINDOWS\system32\DRIVERS\UsbdpFP.sys [2004-10-12 14:53]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-14 19:26:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-14 19:31:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-15 01:31:46
.
2008-01-13 17:16:15 — E O F —
Hello,

Shutdown Kaspersky Anti-Virus The program has been infected with a bad file. So when the program loads the infected file is loading . If you cant shut it down then do this. We will re enable it when were done

  • Go to Start> Run and type in services.msc then press Enter
  • Scroll down to avp - Kaspersky Lab
  • Double Click that service to open it.
  • Click on Stop Service.
  • Then change the Startup Type to Disabled.
  • OK your way out of the program.




Please download OTMoveIt by OldTimer.

  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\drivers\core.cache.dsk

  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it into your next reply.
  • Close OTMoveIt

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.




Open Notepad and copy all the text inside the quote box by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad. Make sure there is no space above and to the left of File::

File::

RenV::
—-a-w 218,376 2008-01-13 15:23:10 C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe



Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]



This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply
together with a new HijackThis log.



I need to see the OtMoveIt log , the new Combofix log and a New HJT log please
Here ya go…

OTMoveIT Log
File move failed. C:\WINDOWS\system32\drivers\core.cache.dsk scheduled to be moved on reboot.

Created on 01/14/2008 21:53:23

[NOTE: I performed the reboot, but Kaspersky keeps starting up. It changes itself to autostart even when I disable it in services.msc]

================================================================================
=

ComboFix 08-01-15.3 - Courtney Porter 2008-01-14 22:01:21.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.200 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: E:\temp\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2007-12-15 to 2008-01-15 )))))))))))))))))))))))))))))))
.

2008-01-14 19:25 . 2008-01-14 22:05 932 ——— C:\WINDOWS\system32\drivers\core.cache.dsk
2008-01-13 11:47 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-13 11:42 . 2008-01-13 11:42 d——– C:\Program Files\Trend Micro
2008-01-13 11:14 . 2007-10-10 17:55 6,065,664 ——— C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-13 11:14 . 2007-06-30 21:31 2,455,488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-13 11:14 . 2007-06-30 21:36 991,232 ——— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-13 11:14 . 2007-10-10 17:55 459,264 ——— C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-13 11:14 . 2007-10-10 17:55 383,488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-13 11:14 . 2007-10-10 17:55 267,776 ——— C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-13 11:14 . 2007-10-10 17:55 63,488 ——— C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-13 11:14 . 2007-10-10 17:55 52,224 ——— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-13 11:14 . 2007-10-10 04:59 13,824 ——— C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-13 10:38 . 2008-01-13 10:38 d——– C:\admin
2008-01-13 10:36 . 2008-01-13 10:36 d——– C:\Program Files\CCleaner
2008-01-13 10:24 . 2008-01-13 10:24 2 –a—— C:\WINDOWS\msoffice.ini
2008-01-13 01:31 . 2005-08-19 10:34 d——– C:\Documents and Settings\Administrator\Application Data\Symantec
2008-01-13 01:31 . 2005-08-19 10:29 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-01-13 01:31 . 2005-08-19 10:38 d——– C:\Documents and Settings\Administrator\Application Data\Gtek
2008-01-09 10:32 . 2008-01-09 10:51 91,492 –a—— C:\WINDOWS\system32\drivers\klin.dat
2008-01-09 10:32 . 2008-01-09 10:51 85,860 –a—— C:\WINDOWS\system32\drivers\klick.dat
2008-01-09 10:23 . 2008-01-09 10:23 d——– C:\Program Files\Kaspersky Lab
2008-01-09 10:23 . 2008-01-14 22:05 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-09 10:22 . 2008-01-14 22:05 2,107,424 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-09 10:22 . 2008-01-14 22:05 33,568 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-09 10:22 . 2008-01-14 22:04 29,252 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-09 10:22 . 2008-01-14 22:04 4,196 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-09 10:19 . 2008-01-09 10:19 d——– C:\KAV
2008-01-08 14:03 . 2008-01-13 01:16 15,360 –a—— C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-01-08 14:03 . 2008-01-13 01:16 15,360 –a—— C:\WINDOWS\system32\ctfmon.exe
2008-01-08 12:46 . 2008-01-13 01:16 114,688 –a—— C:\WINDOWS\system32\igfxpers.exe
2008-01-08 12:46 . 2008-01-13 01:16 94,208 –a—— C:\WINDOWS\system32\igfxtray.exe
2008-01-08 12:46 . 2008-01-13 01:16 77,824 –a—— C:\WINDOWS\system32\hkcmd.exe
2008-01-08 12:44 . 2008-01-13 01:15 188,416 –a—— C:\WINDOWS\system32\ESDUSBMon.EXE
2008-01-08 12:25 . 2008-01-08 12:25 4,286 –a—— C:\WINDOWS\system32\MobileSidewalk.ico
2008-01-08 12:18 . 2008-01-14 19:16 d——– C:\Program Files\Dot1XCfg
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\usmvt3
2008-01-08 12:14 . 2008-01-08 12:20 d——– C:\WINDOWS\system32\drivez4
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\comp2
2008-01-08 12:14 . 2008-01-08 12:14 d——– C:\WINDOWS\system32\cache3
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\ardCo01
2008-01-08 12:14 . 2008-01-08 12:43 d–hs—- C:\WINDOWS\Q291cnRuZXkgUG9ydGVy
2008-01-08 12:14 . 2008-01-08 12:14 86,016 –a—— C:\WINDOWS\system32\drivers\asc35500.sys
2007-12-24 14:42 . 2007-12-24 14:42 d——– C:\Documents and Settings\All Users\Application Data\Dell

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-15 01:16 ——— d—–w C:\Program Files\Dell Support
2008-01-13 16:26 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-13 16:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-13 16:18 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-13 16:17 ——— d—–w C:\Program Files\Yahoo!
2008-01-13 16:15 ——— d—–w C:\Program Files\The Weather Channel FW
2008-01-13 15:18 ——— d—–w C:\Program Files\QuickTime
2008-01-07 21:43 ——— d—–w C:\Program Files\TeleTracker Online
2007-11-16 21:02 ——— d—–w C:\Program Files\Coupons
2007-11-16 16:24 ——— d—–w C:\Documents and Settings\Courtney Porter\Application Data\Zango
2007-11-16 16:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\ZangoSA
2007-11-16 16:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
2004-12-21 23:34 25,214 —-a-w C:\Program Files\dplogo32.ico
.
—-a-w		   218,376 2008-01-13 15:23:10  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp   .exe


((((((((((((((((((((((((((((( snapshot@2008-01-13_12.45.34.14 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-13 18:00:07 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-15 04:01:09 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-13 18:00:07 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-15 04:01:09 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-13 18:00:07 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-15 04:01:09 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-13 18:00:07 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-15 04:01:10 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-13 18:00:07 4,091,904 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-15 04:01:10 4,091,904 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-13 18:00:07 57,344 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-15 04:01:10 57,344 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-13 07:16:18 127,035 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
+ 2008-01-13 07:16:20 172,032 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-13 01:16 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe" [2008-01-13 09:23 218376]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 10:59:36]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 22:44:08]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\Windows Media Player\vilozonil.html
FriendlyName=

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 13:11 233472]

R1 asc35500;asc35500;C:\WINDOWS\system32\drivers\asc35500.sys [2008-01-08 12:14]
R2 Esdpdx01;Esdpdx01;C:\WINDOWS\system32\Drivers\ESDPDX01.SYS [2003-12-25 11:00]
R2 WinRT;WinRT;C:\WINDOWS\system32\drivers\WinRT.sys [2002-12-30 12:33]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
S2 avp ;avp ;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe" [2008-01-13 09:23]
S3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys []
S3 dpK00701;U.are.U Fingerprint Reader Upper Driver;C:\WINDOWS\system32\DRIVERS\dpK00701.sys [2004-10-12 14:51]
S3 TMUSB;EPSON USB Device Driver for TM/BA/EU Printers;C:\WINDOWS\system32\DRIVERS\TMUSBXP.SYS [2007-01-19 08:07]
S3 UsbdpFP;U.are.U Fingerprint Reader Class Driver;C:\WINDOWS\system32\DRIVERS\UsbdpFP.sys [2004-10-12 14:53]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-14 22:06:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-14 22:10:46 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-15 04:10:40
.
2008-01-13 17:16:15 — E O F —

================================================================================
==

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:13:24 PM, on 1/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\WINDOWS\system32\EpStsSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\ESDUSBMon.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\Killer.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://indirect.nextel.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://teletracker.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CDDDD661-2028-4607-A3CE-3F50828625BA}: NameServer = 205.152.37.23,205.152.132.23
O23 - Service: avp - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
O23 - Service: Biometric Authentication Service (DpHost) - Digital Persona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHost.exe
O23 - Service: EPSON ESC/POS Status Service (EPSON ESCPOS Status Service) - SEIKO EPSON Corp. - C:\WINDOWS\SYSTEM32\EpStsSrv.exe
O23 - Service: lmab_device - Lexmark International, Inc. - C:\WINDOWS\system32\LMabcoms.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Windows Media Player\vilozonil.html
O24 - Desktop Component 1: (no name) - http://indirect.nextel.com/secured_site/images/header_bg.gif
O24 - Desktop Component 3: (no name) - http://www.fatcow.com/

–
End of file - 5316 bytes
This is a fairly new variant of Vundo, we may have to uninstall Kaspersky completely from your system, but hang in a bit, I am doing some checking with other helpers and to see how to remove this. I will be back in a bit.
Try doing this and if it does not work we may have to uninstall Kaspersky.

Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe"
O23 - Service: avp - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe




Open Notepad and copy all the text inside the quote box by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad. Make sure there is no space above and to the left of File::

RenV::
—-a-w 218,376 2008-01-13 15:23:10 C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe



Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]



This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply
together with a new HijackThis log.
Sorry this took so long but I was at work… Looks good…



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:36:24 PM, on 1/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\WINDOWS\system32\EpStsSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\ESDUSBMon.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Desktop Search\WindowsSearchFilter.exe
C:\Program Files\Trend Micro\HijackThis\Killer.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://indirect.nextel.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://teletracker.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CDDDD661-2028-4607-A3CE-3F50828625BA}: NameServer = 205.152.37.23,205.152.132.23
O23 - Service: Biometric Authentication Service (DpHost) - Digital Persona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHost.exe
O23 - Service: EPSON ESC/POS Status Service (EPSON ESCPOS Status Service) - SEIKO EPSON Corp. - C:\WINDOWS\SYSTEM32\EpStsSrv.exe
O23 - Service: lmab_device - Lexmark International, Inc. - C:\WINDOWS\system32\LMabcoms.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Windows Media Player\vilozonil.html
O24 - Desktop Component 1: (no name) - http://indirect.nextel.com/secured_site/images/header_bg.gif
O24 - Desktop Component 3: (no name) - http://www.fatcow.com/

–
End of file - 5211 bytes
================================================================================
=========================

ComboFix 08-01-15.3 - Courtney Porter 2008-01-15 18:26:57.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.245 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: E:\temp\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2007-12-16 to 2008-01-16 )))))))))))))))))))))))))))))))
.

2008-01-15 18:29 . 2008-01-15 18:29 932 ——— C:\WINDOWS\system32\drivers\core.cache.dsk
2008-01-13 11:47 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-13 11:42 . 2008-01-13 11:42 d——– C:\Program Files\Trend Micro
2008-01-13 11:14 . 2007-10-10 17:55 6,065,664 ——— C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-13 11:14 . 2007-06-30 21:31 2,455,488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-13 11:14 . 2007-06-30 21:36 991,232 ——— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-13 11:14 . 2007-10-10 17:55 459,264 ——— C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-13 11:14 . 2007-10-10 17:55 383,488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-13 11:14 . 2007-10-10 17:55 267,776 ——— C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-13 11:14 . 2007-10-10 17:55 63,488 ——— C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-13 11:14 . 2007-10-10 17:55 52,224 ——— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-13 11:14 . 2007-10-10 04:59 13,824 ——— C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-13 11:07 . 2008-01-13 11:16 1,374 –a—— C:\WINDOWS\imsins.BAK
2008-01-13 10:38 . 2008-01-13 10:38 d——– C:\admin
2008-01-13 10:36 . 2008-01-13 10:36 d——– C:\Program Files\CCleaner
2008-01-13 10:24 . 2008-01-13 10:24 2 –a—— C:\WINDOWS\msoffice.ini
2008-01-13 01:31 . 2005-08-19 10:34 d——– C:\Documents and Settings\Administrator\Application Data\Symantec
2008-01-13 01:31 . 2005-08-19 10:29 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-01-13 01:31 . 2005-08-19 10:38 d——– C:\Documents and Settings\Administrator\Application Data\Gtek
2008-01-09 10:32 . 2008-01-09 10:51 91,492 –a—— C:\WINDOWS\system32\drivers\klin.dat
2008-01-09 10:32 . 2008-01-09 10:51 85,860 –a—— C:\WINDOWS\system32\drivers\klick.dat
2008-01-09 10:23 . 2008-01-09 10:23 d——– C:\Program Files\Kaspersky Lab
2008-01-09 10:23 . 2008-01-15 08:09 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-09 10:22 . 2008-01-15 18:30 2,146,848 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-09 10:22 . 2008-01-15 18:30 36,896 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-09 10:22 . 2008-01-15 18:29 29,804 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-09 10:22 . 2008-01-15 18:29 4,484 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-09 10:19 . 2008-01-09 10:19 d——– C:\KAV
2008-01-08 14:03 . 2008-01-13 01:16 15,360 –a—— C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-01-08 14:03 . 2008-01-13 01:16 15,360 –a—— C:\WINDOWS\system32\ctfmon.exe
2008-01-08 12:46 . 2008-01-13 01:16 114,688 –a—— C:\WINDOWS\system32\igfxpers.exe
2008-01-08 12:46 . 2008-01-13 01:16 94,208 –a—— C:\WINDOWS\system32\igfxtray.exe
2008-01-08 12:46 . 2008-01-13 01:16 77,824 –a—— C:\WINDOWS\system32\hkcmd.exe
2008-01-08 12:44 . 2008-01-13 01:15 188,416 –a—— C:\WINDOWS\system32\ESDUSBMon.EXE
2008-01-08 12:25 . 2008-01-08 12:25 4,286 –a—— C:\WINDOWS\system32\MobileSidewalk.ico
2008-01-08 12:18 . 2008-01-14 19:16 d——– C:\Program Files\Dot1XCfg
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\usmvt3
2008-01-08 12:14 . 2008-01-08 12:20 d——– C:\WINDOWS\system32\drivez4
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\comp2
2008-01-08 12:14 . 2008-01-08 12:14 d——– C:\WINDOWS\system32\cache3
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\ardCo01
2008-01-08 12:14 . 2008-01-08 12:43 d–hs—- C:\WINDOWS\Q291cnRuZXkgUG9ydGVy
2008-01-08 12:14 . 2008-01-08 12:14 86,016 –a—— C:\WINDOWS\system32\drivers\asc35500.sys
2007-12-24 14:42 . 2007-12-24 14:42 d——– C:\Documents and Settings\All Users\Application Data\Dell

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-15 01:16 ——— d—–w C:\Program Files\Dell Support
2008-01-13 16:26 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-13 16:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-13 16:18 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-13 16:17 ——— d—–w C:\Program Files\Yahoo!
2008-01-13 16:15 ——— d—–w C:\Program Files\The Weather Channel FW
2008-01-13 15:18 ——— d—–w C:\Program Files\QuickTime
2008-01-07 21:43 ——— d—–w C:\Program Files\TeleTracker Online
2007-11-16 21:02 ——— d—–w C:\Program Files\Coupons
2007-11-16 16:24 ——— d—–w C:\Documents and Settings\Courtney Porter\Application Data\Zango
2007-11-16 16:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\ZangoSA
2007-11-16 16:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
2004-12-21 23:34 25,214 —-a-w C:\Program Files\dplogo32.ico
.
—-a-w		   218,376 2008-01-13 15:23:10  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp   .exe


((((((((((((((((((((((((((((( snapshot@2008-01-13_12.45.34.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-07-12 23:28:55 765,952 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\SP2QFE\vgx.dll
+ 2007-03-06 01:22:36 14,048 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\updspapi.dll
- 2008-01-13 18:00:07 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-16 00:26:26 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-13 18:00:07 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-16 00:26:26 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-13 18:00:07 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-16 00:26:26 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-13 18:00:07 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-16 00:26:26 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-13 18:00:07 4,091,904 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-16 00:26:27 4,091,904 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-13 18:00:07 57,344 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-16 00:26:27 57,344 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2007-03-06 01:22:41 213,216 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
+ 2007-08-14 00:54:10 765,952 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
+ 2008-01-13 07:16:18 127,035 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
- 2007-08-14 00:54:10 765,952 —-a-w C:\WINDOWS\system32\dllcache\VGX.dll
+ 2007-07-12 23:31:54 765,952 —-a-w C:\WINDOWS\system32\dllcache\vgx.dll
- 2007-03-06 01:22:33 14,048 —-a-w C:\WINDOWS\system32\spmsg.dll
+ 2007-03-06 01:22:36 14,048 ——w C:\WINDOWS\system32\spmsg.dll
+ 2008-01-13 07:16:20 172,032 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-13 01:16 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 10:59:36]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 22:44:08]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\Windows Media Player\vilozonil.html
FriendlyName=

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 13:11 233472]

R1 asc35500;asc35500;C:\WINDOWS\system32\drivers\asc35500.sys [2008-01-08 12:14]
R2 Esdpdx01;Esdpdx01;C:\WINDOWS\system32\Drivers\ESDPDX01.SYS [2003-12-25 11:00]
R2 WinRT;WinRT;C:\WINDOWS\system32\drivers\WinRT.sys [2002-12-30 12:33]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
S3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys []
S3 dpK00701;U.are.U Fingerprint Reader Upper Driver;C:\WINDOWS\system32\DRIVERS\dpK00701.sys [2004-10-12 14:51]
S3 TMUSB;EPSON USB Device Driver for TM/BA/EU Printers;C:\WINDOWS\system32\DRIVERS\TMUSBXP.SYS [2007-01-19 08:07]
S3 UsbdpFP;U.are.U Fingerprint Reader Class Driver;C:\WINDOWS\system32\DRIVERS\UsbdpFP.sys [2004-10-12 14:53]
S4 avp ;avp ;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe" [2008-01-13 09:23]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-15 18:30:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-15 18:32:49 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-16 00:32:46
ComboFix2.txt 2008-01-15 04:10:51
.
2008-01-15 09:01:31 — E O F —
No problems on the replies, have to work myself.

Nope it did not take, look at your combofix log and you can see the infected program in the Code Box. I am afraid the only other way to clean this is to uninstall Kaspersky

Go to your Add Remove Programs in the Control Panel and uninstall Kaspersky

Then do this

Open Notepad and copy all the text inside the quote box by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad. Make sure there is no space above and to the left of File::

Folder::
C:\Program Files\Kaspersky Lab



Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]



This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply
together with a new HijackThis log.


===================================================

1. Please download The Avenger by Swandog46 to your Desktop.
  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop

2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Files to Delete:
C:\WINDOWS\system32\drivers\core.cache.dsk

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.
  • Under "Script file to execute" choose "Input Script Manually".
  • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
  • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
  • Click Done
  • Now click on the Green Light to begin execution of the script
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log by using Add/Reply



Let me see the Avenger log, the new combofix log and a new HJT log
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\paevluxb

*******************

Script file located at: ijkbpvka

Could not open script file! Error

Could not open script file! Status: 0xc000003b Abort!

=======================================================================

ComboFix 08-01-15.3 - Courtney Porter 2008-01-15 19:21:54.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.213 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: E:\temp\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Kaspersky Lab
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2007-12-16 to 2008-01-16 )))))))))))))))))))))))))))))))
.

2008-01-15 18:29 . 2008-01-15 19:24 932 ——— C:\WINDOWS\system32\drivers\core.cache.dsk
2008-01-13 11:47 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-13 11:42 . 2008-01-13 11:42 d——– C:\Program Files\Trend Micro
2008-01-13 11:14 . 2007-10-10 17:55 6,065,664 ——— C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-13 11:14 . 2007-06-30 21:31 2,455,488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-13 11:14 . 2007-06-30 21:36 991,232 ——— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-13 11:14 . 2007-10-10 17:55 459,264 ——— C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-13 11:14 . 2007-10-10 17:55 383,488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-13 11:14 . 2007-10-10 17:55 267,776 ——— C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-13 11:14 . 2007-10-10 17:55 63,488 ——— C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-13 11:14 . 2007-10-10 17:55 52,224 ——— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-13 11:14 . 2007-10-10 04:59 13,824 ——— C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-13 11:07 . 2008-01-13 11:16 1,374 –a—— C:\WINDOWS\imsins.BAK
2008-01-13 10:38 . 2008-01-13 10:38 d——– C:\admin
2008-01-13 10:36 . 2008-01-13 10:36 d——– C:\Program Files\CCleaner
2008-01-13 10:24 . 2008-01-13 10:24 2 –a—— C:\WINDOWS\msoffice.ini
2008-01-13 01:31 . 2005-08-19 10:34 d——– C:\Documents and Settings\Administrator\Application Data\Symantec
2008-01-13 01:31 . 2005-08-19 10:29 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-01-13 01:31 . 2005-08-19 10:38 d——– C:\Documents and Settings\Administrator\Application Data\Gtek
2008-01-09 10:19 . 2008-01-09 10:19 d——– C:\KAV
2008-01-08 14:03 . 2008-01-13 01:16 15,360 –a—— C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-01-08 14:03 . 2008-01-13 01:16 15,360 –a—— C:\WINDOWS\system32\ctfmon.exe
2008-01-08 12:46 . 2008-01-13 01:16 114,688 –a—— C:\WINDOWS\system32\igfxpers.exe
2008-01-08 12:46 . 2008-01-13 01:16 94,208 –a—— C:\WINDOWS\system32\igfxtray.exe
2008-01-08 12:46 . 2008-01-13 01:16 77,824 –a—— C:\WINDOWS\system32\hkcmd.exe
2008-01-08 12:44 . 2008-01-13 01:15 188,416 –a—— C:\WINDOWS\system32\ESDUSBMon.EXE
2008-01-08 12:25 . 2008-01-08 12:25 4,286 –a—— C:\WINDOWS\system32\MobileSidewalk.ico
2008-01-08 12:18 . 2008-01-14 19:16 d——– C:\Program Files\Dot1XCfg
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\usmvt3
2008-01-08 12:14 . 2008-01-08 12:20 d——– C:\WINDOWS\system32\drivez4
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\comp2
2008-01-08 12:14 . 2008-01-08 12:14 d——– C:\WINDOWS\system32\cache3
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\ardCo01
2008-01-08 12:14 . 2008-01-08 12:43 d–hs—- C:\WINDOWS\Q291cnRuZXkgUG9ydGVy
2008-01-08 12:14 . 2008-01-08 12:14 86,016 –a—— C:\WINDOWS\system32\drivers\asc35500.sys
2007-12-24 14:42 . 2007-12-24 14:42 d——– C:\Documents and Settings\All Users\Application Data\Dell

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-15 01:16 ——— d—–w C:\Program Files\Dell Support
2008-01-13 16:26 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-13 16:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-13 16:18 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-13 16:17 ——— d—–w C:\Program Files\Yahoo!
2008-01-13 16:15 ——— d—–w C:\Program Files\The Weather Channel FW
2008-01-13 15:18 ——— d—–w C:\Program Files\QuickTime
2008-01-07 21:43 ——— d—–w C:\Program Files\TeleTracker Online
2007-11-16 21:02 ——— d—–w C:\Program Files\Coupons
2007-11-16 16:24 ——— d—–w C:\Documents and Settings\Courtney Porter\Application Data\Zango
2007-11-16 16:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\ZangoSA
2007-11-16 16:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-31 11:12 3,590,656 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 17:20 360,064 ——w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 23:40 227,328 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 23:40 227,328 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2004-12-21 23:34 25,214 —-a-w C:\Program Files\dplogo32.ico
.

((((((((((((((((((((((((((((( snapshot@2008-01-13_12.45.34.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-07-12 23:28:55 765,952 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\SP2QFE\vgx.dll
+ 2007-03-06 01:22:36 14,048 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\updspapi.dll
- 2008-01-13 18:00:07 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-16 01:21:49 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-13 18:00:07 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-16 01:21:49 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-13 18:00:07 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-16 01:21:49 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-13 18:00:07 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-16 01:21:50 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-13 18:00:07 4,091,904 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-16 01:21:50 4,091,904 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-13 18:00:07 57,344 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-16 01:21:50 57,344 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2007-03-06 01:22:41 213,216 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
+ 2007-08-14 00:54:10 765,952 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
+ 2008-01-13 07:16:18 127,035 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
- 2007-08-14 00:54:10 765,952 —-a-w C:\WINDOWS\system32\dllcache\VGX.dll
+ 2007-07-12 23:31:54 765,952 —-a-w C:\WINDOWS\system32\dllcache\vgx.dll
- 2007-03-06 01:22:33 14,048 —-a-w C:\WINDOWS\system32\spmsg.dll
+ 2007-03-06 01:22:36 14,048 ——w C:\WINDOWS\system32\spmsg.dll
+ 2008-01-13 07:16:20 172,032 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-13 01:16 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 10:59:36]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 22:44:08]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\Windows Media Player\vilozonil.html
FriendlyName=

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 13:11 233472]

R1 asc35500;asc35500;C:\WINDOWS\system32\drivers\asc35500.sys [2008-01-08 12:14]
R2 Esdpdx01;Esdpdx01;C:\WINDOWS\system32\Drivers\ESDPDX01.SYS [2003-12-25 11:00]
R2 WinRT;WinRT;C:\WINDOWS\system32\drivers\WinRT.sys [2002-12-30 12:33]
S3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys []
S3 dpK00701;U.are.U Fingerprint Reader Upper Driver;C:\WINDOWS\system32\DRIVERS\dpK00701.sys [2004-10-12 14:51]
S3 TMUSB;EPSON USB Device Driver for TM/BA/EU Printers;C:\WINDOWS\system32\DRIVERS\TMUSBXP.SYS [2007-01-19 08:07]
S3 UsbdpFP;U.are.U Fingerprint Reader Class Driver;C:\WINDOWS\system32\DRIVERS\UsbdpFP.sys [2004-10-12 14:53]
S4 avp ;avp ;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe" []

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-15 19:25:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-15 19:27:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-16 01:26:55
ComboFix2.txt 2008-01-16 00:32:50
ComboFix3.txt 2008-01-15 04:10:51
.
2008-01-15 09:01:31 — E O F —

================================================================================
======

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:33:45 PM, on 1/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\WINDOWS\system32\EpStsSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\ESDUSBMon.EXE
C:\Program Files\Windows Desktop Search\WindowsSearchFilter.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\Killer.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://indirect.nextel.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://teletracker.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CDDDD661-2028-4607-A3CE-3F50828625BA}: NameServer = 205.152.37.23,205.152.132.23
O23 - Service: Biometric Authentication Service (DpHost) - Digital Persona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHost.exe
O23 - Service: EPSON ESC/POS Status Service (EPSON ESCPOS Status Service) - SEIKO EPSON Corp. - C:\WINDOWS\SYSTEM32\EpStsSrv.exe
O23 - Service: lmab_device - Lexmark International, Inc. - C:\WINDOWS\system32\LMabcoms.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Windows Media Player\vilozonil.html
O24 - Desktop Component 1: (no name) - http://indirect.nextel.com/secured_site/images/header_bg.gif
O24 - Desktop Component 3: (no name) - http://www.fatcow.com/

–
End of file - 5110 bytes
Looking better but these have to go.

Open Notepad and copy all the text inside the quote box by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::

File::
C:\WINDOWS\system32\drivers\asc35500.sys
C:\WINDOWS\system32\drivers\core.cache.dsk


Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.
Sorry took so long again…kids had to be put to bed. Here you go…Thanks.
==========================================================

ComboFix 08-01-15.3 - Courtney Porter 2008-01-15 21:37:35.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.261 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: E:\temp\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\system32\drivers\asc35500.sys
C:\WINDOWS\system32\drivers\core.cache.dsk
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\asc35500.sys
C:\WINDOWS\system32\drivers\core.cache.dsk

.
((((((((((((((((((((((((( Files Created from 2007-12-16 to 2008-01-16 )))))))))))))))))))))))))))))))
.

2008-01-13 11:47 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-13 11:42 . 2008-01-13 11:42 d——– C:\Program Files\Trend Micro
2008-01-13 11:14 . 2007-10-10 17:55 6,065,664 ——— C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-13 11:14 . 2007-06-30 21:31 2,455,488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-13 11:14 . 2007-06-30 21:36 991,232 ——— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-13 11:14 . 2007-10-10 17:55 459,264 ——— C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-13 11:14 . 2007-10-10 17:55 383,488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-13 11:14 . 2007-10-10 17:55 267,776 ——— C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-13 11:14 . 2007-10-10 17:55 63,488 ——— C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-13 11:14 . 2007-10-10 17:55 52,224 ——— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-13 11:14 . 2007-10-10 04:59 13,824 ——— C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-13 11:07 . 2008-01-13 11:16 1,374 –a—— C:\WINDOWS\imsins.BAK
2008-01-13 10:38 . 2008-01-13 10:38 d——– C:\admin
2008-01-13 10:36 . 2008-01-13 10:36 d——– C:\Program Files\CCleaner
2008-01-13 10:24 . 2008-01-13 10:24 2 –a—— C:\WINDOWS\msoffice.ini
2008-01-13 01:31 . 2005-08-19 10:34 d——– C:\Documents and Settings\Administrator\Application Data\Symantec
2008-01-13 01:31 . 2005-08-19 10:29 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-01-13 01:31 . 2005-08-19 10:38 d——– C:\Documents and Settings\Administrator\Application Data\Gtek
2008-01-09 10:19 . 2008-01-09 10:19 d——– C:\KAV
2008-01-08 14:03 . 2008-01-13 01:16 15,360 –a—— C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-01-08 14:03 . 2008-01-13 01:16 15,360 –a—— C:\WINDOWS\system32\ctfmon.exe
2008-01-08 12:46 . 2008-01-13 01:16 114,688 –a—— C:\WINDOWS\system32\igfxpers.exe
2008-01-08 12:46 . 2008-01-13 01:16 94,208 –a—— C:\WINDOWS\system32\igfxtray.exe
2008-01-08 12:46 . 2008-01-13 01:16 77,824 –a—— C:\WINDOWS\system32\hkcmd.exe
2008-01-08 12:44 . 2008-01-13 01:15 188,416 –a—— C:\WINDOWS\system32\ESDUSBMon.EXE
2008-01-08 12:25 . 2008-01-08 12:25 4,286 –a—— C:\WINDOWS\system32\MobileSidewalk.ico
2008-01-08 12:18 . 2008-01-14 19:16 d——– C:\Program Files\Dot1XCfg
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\usmvt3
2008-01-08 12:14 . 2008-01-08 12:20 d——– C:\WINDOWS\system32\drivez4
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\comp2
2008-01-08 12:14 . 2008-01-08 12:14 d——– C:\WINDOWS\system32\cache3
2008-01-08 12:14 . 2008-01-13 01:46 d——– C:\WINDOWS\system32\ardCo01
2008-01-08 12:14 . 2008-01-08 12:43 d–hs—- C:\WINDOWS\Q291cnRuZXkgUG9ydGVy
2007-12-24 14:42 . 2007-12-24 14:42 d——– C:\Documents and Settings\All Users\Application Data\Dell

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-15 01:16 ——— d—–w C:\Program Files\Dell Support
2008-01-13 16:26 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-13 16:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-13 16:18 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-13 16:17 ——— d—–w C:\Program Files\Yahoo!
2008-01-13 16:15 ——— d—–w C:\Program Files\The Weather Channel FW
2008-01-13 15:18 ——— d—–w C:\Program Files\QuickTime
2008-01-07 21:43 ——— d—–w C:\Program Files\TeleTracker Online
2007-11-16 21:02 ——— d—–w C:\Program Files\Coupons
2007-11-16 16:24 ——— d—–w C:\Documents and Settings\Courtney Porter\Application Data\Zango
2007-11-16 16:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\ZangoSA
2007-11-16 16:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-31 11:12 3,590,656 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 17:20 360,064 ——w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 23:40 227,328 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 23:40 227,328 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2004-12-21 23:34 25,214 —-a-w C:\Program Files\dplogo32.ico
.

((((((((((((((((((((((((((((( snapshot@2008-01-13_12.45.34.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-07-12 23:28:55 765,952 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\SP2QFE\vgx.dll
+ 2007-03-06 01:22:36 14,048 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\updspapi.dll
- 2008-01-13 18:00:07 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-16 03:37:31 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-13 18:00:07 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-16 03:37:31 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-13 18:00:07 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-16 03:37:31 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-13 18:00:07 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-16 03:37:31 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-13 18:00:07 4,091,904 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-16 03:37:31 4,091,904 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-13 18:00:07 57,344 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-16 03:37:32 57,344 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2007-03-06 01:22:41 213,216 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
+ 2007-08-14 00:54:10 765,952 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
+ 2008-01-13 07:16:18 127,035 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
- 2007-08-14 00:54:10 765,952 —-a-w C:\WINDOWS\system32\dllcache\VGX.dll
+ 2007-07-12 23:31:54 765,952 —-a-w C:\WINDOWS\system32\dllcache\vgx.dll
- 2007-03-06 01:22:33 14,048 —-a-w C:\WINDOWS\system32\spmsg.dll
+ 2007-03-06 01:22:36 14,048 ——w C:\WINDOWS\system32\spmsg.dll
+ 2008-01-13 07:16:20 172,032 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-13 01:16 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 10:59:36]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 22:44:08]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\Windows Media Player\vilozonil.html
FriendlyName=

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 13:11 233472]

R2 Esdpdx01;Esdpdx01;C:\WINDOWS\system32\Drivers\ESDPDX01.SYS [2003-12-25 11:00]
R2 WinRT;WinRT;C:\WINDOWS\system32\drivers\WinRT.sys [2002-12-30 12:33]
S1 asc35500;asc35500;C:\WINDOWS\system32\drivers\asc35500.sys []
S3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys []
S3 dpK00701;U.are.U Fingerprint Reader Upper Driver;C:\WINDOWS\system32\DRIVERS\dpK00701.sys [2004-10-12 14:51]
S3 TMUSB;EPSON USB Device Driver for TM/BA/EU Printers;C:\WINDOWS\system32\DRIVERS\TMUSBXP.SYS [2007-01-19 08:07]
S3 UsbdpFP;U.are.U Fingerprint Reader Class Driver;C:\WINDOWS\system32\DRIVERS\UsbdpFP.sys [2004-10-12 14:53]
S4 avp ;avp ;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe" []

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-15 21:41:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-15 21:42:46 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-16 03:42:29
ComboFix2.txt 2008-01-16 01:27:18
ComboFix3.txt 2008-01-16 00:32:50
ComboFix4.txt 2008-01-15 04:10:51
.
2008-01-15 09:01:31 — E O F —
================================================================================
==

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:45:18 PM, on 1/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\DigitalPersona\Bin\DpHost.exe
C:\WINDOWS\system32\EpStsSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\ESDUSBMon.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\Killer.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://indirect.nextel.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://teletracker.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CDDDD661-2028-4607-A3CE-3F50828625BA}: NameServer = 205.152.37.23,205.152.132.23
O23 - Service: Biometric Authentication Service (DpHost) - Digital Persona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHost.exe
O23 - Service: EPSON ESC/POS Status Service (EPSON ESCPOS Status Service) - SEIKO EPSON Corp. - C:\WINDOWS\SYSTEM32\EpStsSrv.exe
O23 - Service: lmab_device - Lexmark International, Inc. - C:\WINDOWS\system32\LMabcoms.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Windows Media Player\vilozonil.html
O24 - Desktop Component 1: (no name) - http://indirect.nextel.com/secured_site/images/header_bg.gif
O24 - Desktop Component 3: (no name) - http://www.fatcow.com/

–
End of file - 5045 bytes
Good Morning,

Things are looking good :thumbup: The file we deleted along with the one that would not delete was a bad driver file that was protecting the other bad file and now there both gone.

I am not looking at any Anti Virus software on your system, in this day and age of all the serious threats going around this is kind of suicidal . Here are some free ones to install, you just need one, more is overkill and will slow up your system.



Here is a free Firewall also.
Zone Alarm Here is a free Firewall from Zone Labs,
.


You also need to update your Java, the old versions let this garbage in.

  • Your Java is out of date and leaving your system vulnerable.
  • Go to your Add-Remove Programs in the Control Panel and uninstall any previous versions of Java (J2SE Runtime Environment)
  • It should have an icon next to it:
    [external image: Posted Image]
    Select it and click Remove.
  • Reboot your system.
  • Then go to the Sun Microsystems and install the update
  • Java Runtime Environment Version 6 Update 3 <–This is what you need to download and install.
  • If you chose the online installation, it will prompt you to run the program.
  • If you chose the offline installation, you will be prompted to save the file and you can run it from wherever you saved it.
  • Then after install you can verify your installation here Sun Java Verify
I like to to do the offline installation and save the setup file in case I may need it in the future



How are things running now???
Good Morning,

Glad things are running well :thumbup:

Just install a firewall , Anti Virus software and update your Java .

Run this system cleaner, its a free program and yours to keep.

Download CCleaner from here to clean temp files from your computer.
  • Double click on the file to start the installation of the program.
  • Select your language and click OK, then next.
  • Read the license agreement and click I Agree.
  • Click next to use the default install location. Click Install then finish to complete installation.
  • Double click the CCleaner shortcut on the desktop to start the program.
  • On the "Windows" tab, under "Internet Explorer," uncheck "Cookies" if you do not want them deleted. (If deleted, you will likely need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
  • If you use either the Firefox or Mozilla browsers, the box to uncheck for "Cookies" is on the Applications tab, under Firefox/Mozilla.
  • Click on the "Options" icon at the left side of the window, then click on "Advanced."
    deselect "Only delete files in Windows Temp folders older than 48 hours."
  • Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.
  • Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.
  • After CCleaner has completed its process, click Exit.
*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!



Malware Complaints
Are you mad ? I mean really mad, seething mad, so mad your ready to spit, mad that you have taken your hard earned dollars to buy a computer only to have some Miscredents, Dirt Bags and Cyber Criminals install a malicious program on your computer without your knowledge or consent. You can post your complaint at the above site. If you live in the U.S.A. you can also report your grievance to your State Attorney Generals Office and the Federal Trade Commission's Bureau of Consumer Protection.


  • How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • Geeks To Go
  • Dslreports



Here are some free programs to install, these are must haves to help keep you secure
  • Spybot Search and Destroy 1.5
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.
  • Spyware Blaster It will prevent most spyware from ever being installed.
  • Spyware Guard It offers realtime protection from spyware installation attempts.
  • Win Patrol This program will warn you when any changes are being made to your system and give
    you the option to deny the change.
  • IE-Spyad
    IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads
    (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 2.0 It has more features and is a lot more secure than IE. It is a very easy and
    painless download and install, it will no way interfere with IE, you can use them both.
  • Zone Alarm Here is a free Firewall from Zone Labs, I
    wouldn't access the internet without it.


Glad we could help

Safe Surfn
Ken

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI