This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Outerinfo / Internet Speed Monitor

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been infected! Any advice would be greatly appreciated!

Here's my HijackThis Logfile:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:47:33 AM, on 1/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\basfipm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Sprint\Pantech\Sprint PCS Connection Manager\PWIUtilityService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
C:\WINDOWS\system32\dla\tfswctrl .exe
C:\Program Files\Dell\QuickSet\quickset .exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Microsoft ActiveSync\wcescomm .exe
C:\Program Files\Common Files\??crosoft.NET\n?tdde.exe
C:\Program Files\iTunes\iTunesHelper .exe
C:\Program Files\QdrModule\QdrModule11.exe
C:\Program Files\QdrPack\QdrPack11.exe
C:\WINDOWS\system32\LVCOMSX .EXE
C:\Program Files\Trillian\trillian.exe
C:\Program Files\QdrModule\QdrModule11 .exe
C:\Program Files\Microsoft ActiveSync\wcescomm .exe
C:\Program Files\Windows Media Player\WMPNSCFG .exe
C:\Program Files\QdrPack\QdrPack11 .exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\DOCUME~1\Ryan\MYDOCU~1\APPATC~1\wowexec.exe
C:\DOCUME~1\Ryan\MYDOCU~1\APPATC~1\wowexec.exe
C:\DOCUME~1\Ryan\MYDOCU~1\APPATC~1\wowexec.exe
C:\DOCUME~1\Ryan\MYDOCU~1\APPATC~1\wowexec.exe
C:\DOCUME~1\Ryan\MYDOCU~1\APPATC~1\wowexec.exe
C:\DOCUME~1\Ryan\MYDOCU~1\APPATC~1\wowexec .exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
F3 - REG:win.ini: load=C:\WINDOWS\system32\ssqpn.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset .exe .exe .exe .exe .exe .exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm .exe"
O4 - HKCU\..\Run: [Sen] "C:\DOCUME~1\Ryan\MYDOCU~1\APPATC~1\wowexec.exe" -vt yazb
O4 - HKCU\..\Run: [Mcoiv] "C:\Program Files\Common Files\??crosoft.NET\n?tdde.exe"
O4 - HKCU\..\Run: [QdrModule11] "C:\Program Files\QdrModule\QdrModule11.exe"
O4 - HKCU\..\Run: [QdrPack11] "C:\Program Files\QdrPack\QdrPack11.exe"
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pantech Utility Service - Sprint Spectrum, L.L.C - C:\Program Files\Sprint\Pantech\Sprint PCS Connection Manager\PWIUtilityService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

–
End of file - 8102 bytes
Hello and welcome to the forum. Sorry about the delay in responding :( If you still need help, Scan again with HijackThis, and copy/paste" a new log file into this thread. Also please describe how your computer behaves at the moment.
I'm getting a lot of pop-ups… especially when I open a new program.

Usually the pop-ups say "Advertisement By Outerinfo"

Here's a new log file:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:23:07 PM, on 1/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\basfipm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Sprint\Pantech\Sprint PCS Connection Manager\PWIUtilityService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Common Files\??crosoft.NET\n?tdde.exe
C:\Program Files\Trillian\trillian.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [e0e5cecc] rundll32.exe "C:\WINDOWS\system32\lnwaapxj.dll",b
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm .exe"
O4 - HKCU\..\Run: [Sen] "C:\DOCUME~1\Ryan\MYDOCU~1\APPATC~1\wowexec.exe" -vt yazb
O4 - HKCU\..\Run: [Mcoiv] "C:\Program Files\Common Files\??crosoft.NET\n?tdde.exe"
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Pantech Utility Service - Sprint Spectrum, L.L.C - C:\Program Files\Sprint\Pantech\Sprint PCS Connection Manager\PWIUtilityService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

–
End of file - 5771 bytes
I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Combo fix kept stalling (for hours) even though I didn't touch the computer after I started it, but I finally got it to finish on like the 5th try. Anyway, here's my log:

ComboFix 08-01-18.5 - Ryan 2008-01-19 12:06:29.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.675 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\Documents and Settings\Ryan\Application Data\macromedia\Flash Player\#SharedObjects\YGT6HJRF\www.broadcaster.com
C:\Documents and Settings\Ryan\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Ryan\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\Ryan\My Documents\APPATC~1
C:\Documents and Settings\Ryan\My Documents\APPATC~1\A?pPatch\
C:\Documents and Settings\Ryan\My Documents\APPATC~1\wowexec .exe
C:\Program Files\Common Files\crosof~1.net
C:\Program Files\Common Files\crosof~1.net\n?tdde.exe
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\QdrDrive9.dll
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\jxpaawnl.ini
C:\WINDOWS\system32\kfsnqqob.dll
C:\WINDOWS\system32\lnwaapxj.dll
C:\WINDOWS\system32\lsqdjbba.ini
C:\WINDOWS\system32\mieflkgi.dll
C:\WINDOWS\system32\npqss.ini
C:\WINDOWS\system32\npqss.ini2
C:\WINDOWS\system32\rbtnbxxi.ini
C:\WINDOWS\system32\sidhajdw.dll
C:\WINDOWS\system32\ssqpn.dll
C:\WINDOWS\system32\ukmwddbf.dll
C:\WINDOWS\system32\ycsyiync.ini

.
((((((((((((((((((((((((( Files Created from 2007-12-19 to 2008-01-19 )))))))))))))))))))))))))))))))
.

2008-01-18 22:53 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-18 16:49 . 2008-01-18 16:49 4,286 –a—— C:\WINDOWS\system32\MobileSidewalk.ico
2008-01-18 07:12 . 2008-01-18 07:12 1,075,464 –ahs—- C:\WINDOWS\system32\ycsyiync.tmp
2008-01-16 10:24 . 2008-01-16 10:24 0 –a—— C:\WINDOWS\cfgedit.INI
2008-01-16 09:36 . 2008-01-16 09:33 512,096 –a—— C:\WINDOWS\system32\drivers\amon.sys
2008-01-16 09:36 . 2008-01-16 09:33 298,104 –a—— C:\WINDOWS\system32\imon.dll
2008-01-16 09:36 . 2008-01-16 09:33 15,424 –a—— C:\WINDOWS\system32\drivers\nod32drv.sys
2008-01-15 16:22 . 2008-01-16 09:21 d——– C:\Program Files\Symantec
2008-01-15 16:22 . 2008-01-16 09:21 d——– C:\Program Files\Common Files\Symantec Shared
2008-01-15 16:22 . 2008-01-16 09:21 d——– C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-14 09:36 . 2008-01-14 09:36 d——– C:\Program Files\Trend Micro
2008-01-14 08:26 . 2008-01-14 08:26 d——– C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-01-13 18:03 . 2008-01-16 09:44 221,184 –a—— C:\WINDOWS\system32\LVCOMSX .EXE
2008-01-13 02:19 . 2008-01-13 02:19 749 -rah—– C:\WINDOWS\WindowsShell.Manifest
2008-01-13 02:19 . 2008-01-13 02:19 749 -rah—– C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-01-13 02:19 . 2008-01-13 02:19 749 -rah—– C:\WINDOWS\system32\sapi.cpl.manifest
2008-01-13 02:19 . 2008-01-13 02:19 749 -rah—– C:\WINDOWS\system32\ncpa.cpl.manifest
2008-01-13 02:19 . 2008-01-13 02:19 488 -rah—– C:\WINDOWS\system32\logonui.exe.manifest
2008-01-13 01:21 . 2004-08-04 00:56 152,576 –a—— C:\WINDOWS\system32\irftp.exe
2008-01-13 01:21 . 2004-08-03 23:00 87,424 –a—— C:\WINDOWS\system32\drivers\irda.sys
2008-01-13 01:21 . 2004-08-04 00:56 27,136 –a—— C:\WINDOWS\system32\irmon.dll
2008-01-13 01:21 . 2004-08-04 00:56 8,192 –a—— C:\WINDOWS\system32\wshirda.dll
2008-01-13 00:04 . 2008-01-13 00:04 d——– C:\Program Files\Sigmatel
2008-01-13 00:02 . 2001-08-17 13:51 19,584 –a—— C:\WINDOWS\system32\drivers\rasirda.sys
2008-01-12 23:57 . 2004-08-04 07:00 24,661 –a—— C:\WINDOWS\system32\spxcoins.dll
2008-01-12 23:57 . 2004-08-04 07:00 13,312 –a—— C:\WINDOWS\system32\irclass.dll
2008-01-12 17:13 . 2008-01-12 17:13 d——– C:\WINDOWS\dell
2008-01-10 19:17 . 2008-01-10 19:17 d——– C:\Program Files\iPod
2008-01-10 19:14 . 2007-10-31 14:09 30,464 –a—— C:\WINDOWS\system32\drivers\usbaapl.sys
2008-01-03 12:10 . 2008-01-03 12:10 d——– C:\Program Files\Autodesk
2008-01-03 12:09 . 2008-01-03 12:09 d——– C:\Program Files\AnswerWorks 4.0
2008-01-03 12:08 . 2008-01-03 12:09 d——– C:\Program Files\Common Files\Autodesk Shared
2008-01-03 12:08 . 2008-01-03 12:10 d——– C:\Program Files\AutoCAD 2004
2008-01-03 12:08 . 2008-01-03 12:27 d——– C:\Documents and Settings\Ryan\Application Data\Autodesk
2008-01-03 12:08 . 2008-01-03 12:08 d——– C:\Documents and Settings\All Users\Application Data\Autodesk
2007-12-30 00:52 . 2007-12-30 00:52 d——– C:\Program Files\Eltima Software
2007-12-29 16:18 . 2004-03-29 16:23 90,112 –a—— C:\WINDOWS\unvise32.exe
2007-12-29 16:17 . 2008-01-15 12:10 d——– C:\Program Files\Handmark

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-19 17:05 ——— d—–w C:\Program Files\Trillian
2008-01-16 16:06 ——— d—–w C:\Program Files\QuickTime
2008-01-16 16:06 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-01-16 15:48 ——— d—–w C:\Program Files\iTunes
2008-01-16 15:47 ——— d—–w C:\Program Files\Apoint
2008-01-11 00:21 ——— d—–w C:\Program Files\Apple Software Update
2008-01-09 14:45 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-30 05:45 ——— d—–w C:\Program Files\FLV Player
2007-12-29 05:19 ——— d—–w C:\Program Files\Stellarium
2007-12-18 21:38 ——— d—–w C:\Program Files\TripleA
2007-12-10 14:40 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-10 14:39 ——— d—–w C:\Program Files\SONY
2007-12-09 19:33 ——— d—–w C:\Documents and Settings\Ryan\Application Data\My Games
2007-12-03 17:26 ——— d—–w C:\Documents and Settings\Ryan\Application Data\AdobeUM
2007-12-03 12:47 0 —-a-w C:\WINDOWS\system32\drivers\lvuvc.hs
2007-12-03 04:23 ——— d—–w C:\Program Files\Armadillo Run Demo
2007-11-26 05:03 ——— d—–w C:\Program Files\LimeWire
2003-12-04 17:46 2,832,784 -c–a-w C:\Program Files\CADtools.aip
.
—-a-w		   155,648 2008-01-16 14:43:51  C:\Program Files\Apoint\Apoint .exe
—-a-w		   344,064 2008-01-16 14:43:51  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w		   110,592 2008-01-16 14:43:57  C:\Program Files\Common Files\Sonic\Update Manager\sgtray .exe
—-a-w			53,248 2008-01-16 14:43:57  C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
—-a-w		   949,376 2008-01-16 15:24:13  C:\Program Files\ESET\nod32kui .exe
—-a-w		   267,048 2008-01-16 14:44:15  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w		   132,496 2008-01-16 14:44:01  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		   204,288 2008-01-16 14:44:28  C:\Program Files\Windows Media Player\WMPNSCFG .exe
—-a-w		   208,952 2008-01-15 14:45:47  C:\WINDOWS\ime\imjp8_1\IMJPMIG .EXE
—-a-w			44,032 2008-01-15 14:45:55  C:\WINDOWS\ime\imkr6_1\IMEKRMIG .EXE
—-a-w		   221,184 2008-01-16 14:44:03  C:\WINDOWS\system32\LVCOMSX .EXE
—-a-w		   127,035 2008-01-16 14:43:58  C:\WINDOWS\system32\dla\tfswctrl .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EasyDVDMon"="" []
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [ ]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm .exe" [ ]
"Sen"="C:\DOCUME~1\Ryan\MYDOCU~1\APPATC~1\wowexec.exe" [ ]
"Mcoiv"="C:\Program Files\Common Files\??crosoft.NET\n?tdde.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [ ]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-05-10 09:48 94208 C:\WINDOWS\KHALMNPR.Exe]

C:\Documents and Settings\Ryan\Start Menu\Programs\Startup\
Trillian.lnk - C:\Program Files\Trillian\trillian.exe [2007-04-29 23:00:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebcayv]
gebcayv.dll

R0 vdevax;vdevax;C:\WINDOWS\system32\DRIVERS\vdevax.sys [2002-11-05 13:17]
R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepKE.sys [2006-06-30 00:53]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2004-05-03 08:26]
R3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-09-01 13:11]
S3 axsaki;axsaki;C:\WINDOWS\system32\DRIVERS\axsaki.sys [2003-03-30 20:38]
S3 axskbus;axskbus;C:\WINDOWS\system32\DRIVERS\axskbus.sys [2003-03-28 10:58]
S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys [2006-12-14 10:27]
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys [2007-02-13 00:12]
S3 pxfhbus;PANTECH PC Card Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\pxfhbus.sys [2006-10-12 07:44]
S3 pxfhmdfl;PANTECH PC Card Filter;C:\WINDOWS\system32\DRIVERS\pxfhmdfl.sys [2006-10-12 07:44]
S3 pxfhmdm;PANTECH PC Card Drivers;C:\WINDOWS\system32\DRIVERS\pxfhmdm.sys [2006-10-12 07:44]
S3 pxfhserd;PANTECH PC Card Diagnostic Serial Port (WDM);C:\WINDOWS\system32\DRIVERS\pxfhserd.sys [2006-10-12 07:44]
S3 vbusax;vbusax;C:\WINDOWS\system32\DRIVERS\vbusax.sys [2002-11-05 13:17]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-19 12:08:38
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-19 12:09:43
ComboFix-quarantined-files.txt 2008-01-19 17:09:27
.
2008-01-19 08:00:24 — E O F —
Here's the Hijack This log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:13:58 PM, on 1/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\basfipm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Sprint\Pantech\Sprint PCS Connection Manager\PWIUtilityService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm .exe"
O4 - HKCU\..\Run: [Sen] "C:\DOCUME~1\Ryan\MYDOCU~1\APPATC~1\wowexec.exe" -vt yazb
O4 - HKCU\..\Run: [Mcoiv] "C:\Program Files\Common Files\??crosoft.NET\n?tdde.exe"
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O20 - Winlogon Notify: gebcayv - gebcayv.dll (file missing)
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Pantech Utility Service - Sprint Spectrum, L.L.C - C:\Program Files\Sprint\Pantech\Sprint PCS Connection Manager\PWIUtilityService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

–
End of file - 6070 bytes
By the way, I can't get wireless networking to work anymore. I tried repairing the connection but it said it couldn't complete the repair because it couldn't connect to a wireless network (even though I'm in an area with several available networks).
Open notepad and copy/paste the text in the Codebox below into it:

File::
C:\WINDOWS\system32\ycsyiync.tmp
C:\WINDOWS\system32\drivers\lvuvc.hs

RenV::
C:\Program Files\Apoint\Apoint .exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray .exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
C:\Program Files\ESET\nod32kui .exe
C:\Program Files\iTunes\iTunesHelper .exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\Windows Media Player\WMPNSCFG .exe
C:\WINDOWS\ime\imjp8_1\IMJPMIG .EXE
C:\WINDOWS\ime\imkr6_1\IMEKRMIG .EXE
C:\WINDOWS\system32\LVCOMSX .EXE
C:\WINDOWS\system32\dla\tfswctrl .exe

Driver::
lvuvc

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sen"=-
"Mcoiv"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebcayv]


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
My computer seems to be running pretty well… No pop-ups and it seems faster than before… I haven't tried connecting to a wireless network…

Here's my ComboFix Log:

ComboFix 08-01-18.5 - Ryan 2008-01-19 14:05:20.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.681 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Ryan\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
File::C:\WINDOWS\system32\ycsyiync.tmpC:\WINDOWS\system32\drivers\lvuvc.hsRenV::C:\Program Files\Apoint\Apoint .exeC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exeC:\Program Files\Common Files\Sonic\Update Manager\sgtray .exeC:\Program Files\CyberLink\PowerDVD\DVDLauncher .exeC:\Program Files\ESET\nod32kui .exeC:\Program Files\iTunes\iTunesHelper .exeC:\Program Files\Java\jre1.6.0_03\bin\jusched .exeC:\Program Files\Windows Media Player\WMPNSCFG .exeC:\WINDOWS\ime\imjp8_1\IMJPMIG .EXEC:\WINDOWS\ime\imkr6_1\IMEKRMIG .EXEC:\WINDOWS\system32\LVCOMSX .EXEC:\WINDOWS\system32\dla\tfswctrl .exeDriver::lvuvcRegistry::[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Sen"=-"Mcoiv"=-[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebcayv]
.

((((((((((((((((((((((((( Files Created from 2007-12-19 to 2008-01-19 )))))))))))))))))))))))))))))))
.

2008-01-18 22:53 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-18 16:49 . 2008-01-18 16:49 4,286 –a—— C:\WINDOWS\system32\MobileSidewalk.ico
2008-01-18 07:12 . 2008-01-18 07:12 1,075,464 –ahs—- C:\WINDOWS\system32\ycsyiync.tmp
2008-01-16 10:24 . 2008-01-16 10:24 0 –a—— C:\WINDOWS\cfgedit.INI
2008-01-16 09:36 . 2008-01-16 09:33 512,096 –a—— C:\WINDOWS\system32\drivers\amon.sys
2008-01-16 09:36 . 2008-01-16 09:33 298,104 –a—— C:\WINDOWS\system32\imon.dll
2008-01-16 09:36 . 2008-01-16 09:33 15,424 –a—— C:\WINDOWS\system32\drivers\nod32drv.sys
2008-01-15 16:22 . 2008-01-16 09:21 d——– C:\Program Files\Symantec
2008-01-15 16:22 . 2008-01-16 09:21 d——– C:\Program Files\Common Files\Symantec Shared
2008-01-15 16:22 . 2008-01-16 09:21 d——– C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-14 09:36 . 2008-01-14 09:36 d——– C:\Program Files\Trend Micro
2008-01-14 08:26 . 2008-01-14 08:26 d——– C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-01-13 18:03 . 2008-01-16 09:44 221,184 –a—— C:\WINDOWS\system32\LVCOMSX .EXE
2008-01-13 02:19 . 2008-01-13 02:19 749 -rah—– C:\WINDOWS\WindowsShell.Manifest
2008-01-13 02:19 . 2008-01-13 02:19 749 -rah—– C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-01-13 02:19 . 2008-01-13 02:19 749 -rah—– C:\WINDOWS\system32\sapi.cpl.manifest
2008-01-13 02:19 . 2008-01-13 02:19 749 -rah—– C:\WINDOWS\system32\ncpa.cpl.manifest
2008-01-13 02:19 . 2008-01-13 02:19 488 -rah—– C:\WINDOWS\system32\logonui.exe.manifest
2008-01-13 01:21 . 2004-08-04 00:56 152,576 –a—— C:\WINDOWS\system32\irftp.exe
2008-01-13 01:21 . 2004-08-03 23:00 87,424 –a—— C:\WINDOWS\system32\drivers\irda.sys
2008-01-13 01:21 . 2004-08-04 00:56 27,136 –a—— C:\WINDOWS\system32\irmon.dll
2008-01-13 01:21 . 2004-08-04 00:56 8,192 –a—— C:\WINDOWS\system32\wshirda.dll
2008-01-13 00:04 . 2008-01-13 00:04 d——– C:\Program Files\Sigmatel
2008-01-13 00:02 . 2001-08-17 13:51 19,584 –a—— C:\WINDOWS\system32\drivers\rasirda.sys
2008-01-12 23:57 . 2004-08-04 07:00 24,661 –a—— C:\WINDOWS\system32\spxcoins.dll
2008-01-12 23:57 . 2004-08-04 07:00 13,312 –a—— C:\WINDOWS\system32\irclass.dll
2008-01-12 17:13 . 2008-01-12 17:13 d——– C:\WINDOWS\dell
2008-01-10 19:17 . 2008-01-10 19:17 d——– C:\Program Files\iPod
2008-01-10 19:14 . 2007-10-31 14:09 30,464 –a—— C:\WINDOWS\system32\drivers\usbaapl.sys
2008-01-03 12:10 . 2008-01-03 12:10 d——– C:\Program Files\Autodesk
2008-01-03 12:09 . 2008-01-03 12:09 d——– C:\Program Files\AnswerWorks 4.0
2008-01-03 12:08 . 2008-01-03 12:09 d——– C:\Program Files\Common Files\Autodesk Shared
2008-01-03 12:08 . 2008-01-03 12:10 d——– C:\Program Files\AutoCAD 2004
2008-01-03 12:08 . 2008-01-03 12:27 d——– C:\Documents and Settings\Ryan\Application Data\Autodesk
2008-01-03 12:08 . 2008-01-03 12:08 d——– C:\Documents and Settings\All Users\Application Data\Autodesk
2007-12-30 00:52 . 2007-12-30 00:52 d——– C:\Program Files\Eltima Software
2007-12-29 16:18 . 2004-03-29 16:23 90,112 –a—— C:\WINDOWS\unvise32.exe
2007-12-29 16:17 . 2008-01-15 12:10 d——– C:\Program Files\Handmark

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-19 19:04 ——— d—–w C:\Program Files\Trillian
2008-01-16 16:06 ——— d—–w C:\Program Files\QuickTime
2008-01-16 16:06 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-01-16 15:48 ——— d—–w C:\Program Files\iTunes
2008-01-16 15:47 ——— d—–w C:\Program Files\Apoint
2008-01-11 00:21 ——— d—–w C:\Program Files\Apple Software Update
2008-01-09 14:45 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-30 05:45 ——— d—–w C:\Program Files\FLV Player
2007-12-29 05:19 ——— d—–w C:\Program Files\Stellarium
2007-12-18 21:38 ——— d—–w C:\Program Files\TripleA
2007-12-10 14:40 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-10 14:39 ——— d—–w C:\Program Files\SONY
2007-12-09 19:33 ——— d—–w C:\Documents and Settings\Ryan\Application Data\My Games
2007-12-03 17:26 ——— d—–w C:\Documents and Settings\Ryan\Application Data\AdobeUM
2007-12-03 12:47 0 —-a-w C:\WINDOWS\system32\drivers\lvuvc.hs
2007-12-03 04:23 ——— d—–w C:\Program Files\Armadillo Run Demo
2007-11-26 05:03 ——— d—–w C:\Program Files\LimeWire
2003-12-04 17:46 2,832,784 -c–a-w C:\Program Files\CADtools.aip
.
—-a-w		   155,648 2008-01-16 14:43:51  C:\Program Files\Apoint\Apoint .exe
—-a-w		   344,064 2008-01-16 14:43:51  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w		   110,592 2008-01-16 14:43:57  C:\Program Files\Common Files\Sonic\Update Manager\sgtray .exe
—-a-w			53,248 2008-01-16 14:43:57  C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
—-a-w		   949,376 2008-01-16 15:24:13  C:\Program Files\ESET\nod32kui .exe
—-a-w		   267,048 2008-01-16 14:44:15  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w		   132,496 2008-01-16 14:44:01  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		   204,288 2008-01-16 14:44:28  C:\Program Files\Windows Media Player\WMPNSCFG .exe
—-a-w		   208,952 2008-01-15 14:45:47  C:\WINDOWS\ime\imjp8_1\IMJPMIG .EXE
—-a-w			44,032 2008-01-15 14:45:55  C:\WINDOWS\ime\imkr6_1\IMEKRMIG .EXE
—-a-w		   221,184 2008-01-16 14:44:03  C:\WINDOWS\system32\LVCOMSX .EXE
—-a-w		   127,035 2008-01-16 14:43:58  C:\WINDOWS\system32\dla\tfswctrl .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EasyDVDMon"="" []
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [ ]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm .exe" [ ]
"Sen"="C:\DOCUME~1\Ryan\MYDOCU~1\APPATC~1\wowexec.exe" [ ]
"Mcoiv"="C:\Program Files\Common Files\??crosoft.NET\n?tdde.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [ ]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-05-10 09:48 94208 C:\WINDOWS\KHALMNPR.Exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebcayv]
gebcayv.dll

R0 vdevax;vdevax;C:\WINDOWS\system32\DRIVERS\vdevax.sys [2002-11-05 13:17]
R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepKE.sys [2006-06-30 00:53]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2004-05-03 08:26]
R3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-09-01 13:11]
S3 axsaki;axsaki;C:\WINDOWS\system32\DRIVERS\axsaki.sys [2003-03-30 20:38]
S3 axskbus;axskbus;C:\WINDOWS\system32\DRIVERS\axskbus.sys [2003-03-28 10:58]
S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys [2006-12-14 10:27]
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys [2007-02-13 00:12]
S3 pxfhbus;PANTECH PC Card Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\pxfhbus.sys [2006-10-12 07:44]
S3 pxfhmdfl;PANTECH PC Card Filter;C:\WINDOWS\system32\DRIVERS\pxfhmdfl.sys [2006-10-12 07:44]
S3 pxfhmdm;PANTECH PC Card Drivers;C:\WINDOWS\system32\DRIVERS\pxfhmdm.sys [2006-10-12 07:44]
S3 pxfhserd;PANTECH PC Card Diagnostic Serial Port (WDM);C:\WINDOWS\system32\DRIVERS\pxfhserd.sys [2006-10-12 07:44]
S3 vbusax;vbusax;C:\WINDOWS\system32\DRIVERS\vbusax.sys [2002-11-05 13:17]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-19 14:09:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-19 14:10:58
ComboFix-quarantined-files.txt 2008-01-19 19:10:42
ComboFix2.txt 2008-01-19 17:09:43
.
2008-01-19 08:00:24 — E O F —
Here's the new HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:14:22 PM, on 1/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\basfipm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Sprint\Pantech\Sprint PCS Connection Manager\PWIUtilityService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm .exe"
O4 - HKCU\..\Run: [Sen] "C:\DOCUME~1\Ryan\MYDOCU~1\APPATC~1\wowexec.exe" -vt yazb
O4 - HKCU\..\Run: [Mcoiv] "C:\Program Files\Common Files\??crosoft.NET\n?tdde.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O20 - Winlogon Notify: gebcayv - gebcayv.dll (file missing)
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Pantech Utility Service - Sprint Spectrum, L.L.C - C:\Program Files\Sprint\Pantech\Sprint PCS Connection Manager\PWIUtilityService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

–
End of file - 5967 bytes
Do you see the ones in the codebox? Those are / were infected and might require you to re-install them.

You have a few infection which infects legitimate files, it can be a bit of a pain

1. Download RenV.exe by sUBs to your desktop
2. Double click on it to run it
It will search your system drive looking for any modified .exe file and will produce a log for you.
3. Please copy and paste this report to your reply
RenV Log:

Ran on Sat 01/19/2008 - 14:26:08.37

—-a-w		   155,648 2008-01-16 14:43:51  C:\Program Files\Apoint\Apoint .exe
—-a-w		   344,064 2008-01-16 14:43:51  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w		   110,592 2008-01-16 14:43:57  C:\Program Files\Common Files\Sonic\Update Manager\sgtray .exe
—-a-w			53,248 2008-01-16 14:43:57  C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
—-a-w		   949,376 2008-01-16 15:24:13  C:\Program Files\ESET\nod32kui .exe
—-a-w		   267,048 2008-01-16 14:44:15  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w		   132,496 2008-01-16 14:44:01  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		   204,288 2008-01-16 14:44:28  C:\Program Files\Windows Media Player\WMPNSCFG .exe
—-a-w		   208,952 2008-01-15 14:45:47  C:\WINDOWS\ime\imjp8_1\IMJPMIG .EXE
—-a-w			44,032 2008-01-15 14:45:55  C:\WINDOWS\ime\imkr6_1\IMEKRMIG .EXE
—-a-w		   221,184 2008-01-16 14:44:03  C:\WINDOWS\system32\LVCOMSX .EXE
—-a-w		   127,035 2008-01-16 14:43:58  C:\WINDOWS\system32\dla\tfswctrl .exe

 Entries:			   12  (12)
 Directories:			0  Files:			12
 Bytes:		  2,817,963  Blocks:		5,507
  • Copy the entire contents of the Code Box below to Notepad.
  • Name the file as Log.txt (Overwrite the existing one)
  • Change the Save as Type to All Files
  • and Save it on the desktop
C:\Program Files\Apoint\Apoint .exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray .exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
C:\Program Files\ESET\nod32kui .exe
C:\Program Files\iTunes\iTunesHelper .exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\Windows Media Player\WMPNSCFG .exe
C:\WINDOWS\ime\imjp8_1\IMJPMIG .EXE
C:\WINDOWS\ime\imkr6_1\IMEKRMIG .EXE
C:\WINDOWS\system32\LVCOMSX .EXE
C:\WINDOWS\system32\dla\tfswctrl .exe

[external image: Posted Image]


Refering to the picture above, drag Log.txt into RenV.exe and attach the resulting report to your reply.
New RenV Log:

Ran on Sat 01/19/2008 - 14:42:39.89

—-a-w		   155,648 2008-01-16 14:43:51  C:\Program Files\Apoint\Apoint .exe
—-a-w		   344,064 2008-01-16 14:43:51  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w		   110,592 2008-01-16 14:43:57  C:\Program Files\Common Files\Sonic\Update Manager\sgtray .exe
—-a-w			53,248 2008-01-16 14:43:57  C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
—-a-w		   949,376 2008-01-16 15:24:13  C:\Program Files\ESET\nod32kui .exe
—-a-w		   267,048 2008-01-16 14:44:15  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w		   132,496 2008-01-16 14:44:01  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		   204,288 2008-01-16 14:44:28  C:\Program Files\Windows Media Player\WMPNSCFG .exe
—-a-w		   208,952 2008-01-15 14:45:47  C:\WINDOWS\ime\imjp8_1\IMJPMIG .EXE
—-a-w			44,032 2008-01-15 14:45:55  C:\WINDOWS\ime\imkr6_1\IMEKRMIG .EXE
—-a-w		   221,184 2008-01-16 14:44:03  C:\WINDOWS\system32\LVCOMSX .EXE
—-a-w		   127,035 2008-01-16 14:43:58  C:\WINDOWS\system32\dla\tfswctrl .exe

 Entries:			   12  (12)
 Directories:			0  Files:			12
 Bytes:		  2,817,963  Blocks:		5,507

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI