I turned on my computer yesterday and discovered it kept having boxes pop up asking me to install a chinese language pack and the antivirus would start, but abruptly stop. i ran hijack this, combofix and smitfraudfix and the popups stopped, but the antivirus still gets abruptly closed. here is my hijack this log, combofix log and smitfraudfix log, in that order:

by the way, hijackthis would not run as originally named, so i re-named it to "tonsils" (dont ask, im a medical student. it was the topic of the day)

Logfile of HijackThis v1.99.1
Scan saved at 12:39:54 AM, on 2/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINSETUP\System32\smss.exe
C:\WINSETUP\system32\winlogon.exe
C:\WINSETUP\system32\services.exe
C:\WINSETUP\system32\lsass.exe
C:\WINSETUP\system32\svchost.exe
C:\WINSETUP\System32\svchost.exe
C:\WINSETUP\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINSETUP\system32\svchost.exe
C:\WINSETUP\system32\svchost.exe
C:\WINSETUP\system32\svchost.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\WINSETUP\System32\svchost.exe
C:\WINSETUP\System32\svchost.exe
C:\WINSETUP\system32\svchost.exe
C:\WINSETUP\system32\Mousie.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINSETUP\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINSETUP\system32\ctfmon.exe
C:\Documents and Settings\Home\Desktop\tonsils.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINSETUP\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINSETUP\system32\Macromed\Flash\FlashUtil9d.exe
O4 - Global Startup: Hotsync.lnk = C:\Program Files\Palm\Hotsync.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testgen/i…GenXInstall.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O20 - Winlogon Notify: BITS - C:\WINSETUP\System32\Systen.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe



ComboFix 08-02-25.2 - Home 2008-02-25 0:13:13.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.253 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINSETUP\2588752.dll

.
((((((((((((((((((((((((( Files Created from 2008-01-25 to 2008-02-25 )))))))))))))))))))))))))))))))
.

2008-02-24 23:40 . 2008-02-24 23:40 2,048 –a—— C:\Documents and Settings\Home\afc9fe2f418b00a0.bat
2008-02-24 00:58 . 2008-02-24 00:58 d——– C:\WINSETUP\Internet Logs
2008-02-23 11:30 . 2008-02-24 23:40 33,125 –a—— C:\WINSETUP\system32\HHHCompress.dll
2008-02-23 11:30 . 2008-02-24 23:40 11,947 –a—— C:\WINSETUP\system32\NNNNNN1029.exe
2008-02-23 11:30 . 2008-02-23 11:30 176 –a—— C:\abbd4a7e989a1962231.bat
2008-02-23 10:59 . 2008-02-25 00:09 54,156 –ah—– C:\WINSETUP\QTFont.qfn
2008-02-23 10:59 . 2008-02-23 10:59 1,409 –a—— C:\WINSETUP\QTFont.for
2008-02-23 00:52 . 2008-02-23 00:56 2,096 –a—— C:\WINSETUP\system32\tmp.reg
2008-02-23 00:36 . 2008-02-23 00:36 d——– C:\VundoFix Backups
2008-02-23 00:07 . 2008-02-25 00:00 949 –a—— C:\WINSETUP\system32\qsrfcq.key
2008-02-23 00:07 . 2008-02-25 00:00 949 –a—— C:\WINSETUP\system32\cexysu.Key
2008-02-22 23:54 . 2008-02-22 23:54 8,192 –a—— C:\WINSETUP\269555830.dat
2008-02-22 23:30 . 2008-02-22 23:31 421,888 –a—— C:\WINSETUP\system32\Seven.exe
2008-02-22 23:29 . 2008-02-22 23:29 8,192 –a—— C:\WINSETUP\268040461.dat
2008-02-22 22:58 . 2008-02-22 22:58 8,192 –a—— C:\WINSETUP\266218061.dat
2008-02-22 22:53 . 2008-02-23 00:14 35,328 –a—— C:\WINSETUP\system32\NetGuy_Update.exe
2008-02-22 22:09 . 2008-02-22 22:09 21,120 –a—— C:\WINSETUP\system32\drivers\winsys.sys
2008-02-22 22:08 . 2008-02-22 22:08 55,296 –a—— C:\WINSETUP\system32\wincom.exe
2008-02-22 16:47 . 2008-02-22 16:47 71,236 –a—— C:\WINSETUP\system32\qsrfcq.dll
2008-02-22 16:47 . 2008-02-22 16:47 1 –a—— C:\WINSETUP\system32\000631de.ini
2008-02-22 13:49 . 2008-02-23 00:31 1,430 –a—— C:\WINSETUP\system32\NetGuy.ini
2008-02-22 13:48 . 2008-02-23 11:41 258,048 –a—— C:\WINSETUP\system32\w2.exe
2008-02-22 13:48 . 2008-02-23 00:14 203,776 –a—— C:\WINSETUP\ThunderBHONew.dll
2008-02-22 13:48 . 2008-02-23 00:14 116,567 –a—— C:\WINSETUP\d39.exe
2008-02-22 13:48 . 2008-02-22 13:48 76,288 —hs—- C:\WINSETUP\system32\nbjs.dll
2008-02-22 13:48 . 2008-02-22 13:48 36,864 –a—— C:\WINSETUP\mrofinu565.exe.tmp
2008-02-22 13:48 . 2008-02-23 00:28 35,328 –a—— C:\WINSETUP\system32\exe.exe
2008-02-22 13:48 . 2008-02-23 00:44 28,160 –a—— C:\WINSETUP\system32\NetGuy_BHO.dll
2008-02-22 13:48 . 2008-02-23 11:41 8,192 –a—— C:\WINSETUP\system32\1.hiv
2008-02-22 13:47 . 2008-02-22 13:47 d——– C:\WINSETUP\system32\inf
2008-02-22 13:47 . 2008-02-24 23:50 70,778 –a—— C:\WINSETUP\system32\q1.exe
2008-02-22 13:47 . 2008-02-22 13:47 36,864 –a—— C:\WINSETUP\mrofinu20.exe.tmp
2008-02-22 13:40 . 2008-02-22 13:40 19 –a—— C:\WINSETUP\system32\havser.ini
2008-02-22 13:37 . 2008-02-22 13:40 5,736,738 –a—— C:\WINSETUP\system32\url1.exe
2008-02-22 13:37 . 2008-02-22 13:37 34,816 –a—— C:\WINSETUP\system32\sechost.exe
2008-02-22 13:37 . 2008-02-22 13:37 20,480 –a—— C:\WINSETUP\system32\cifmon.exe
2008-02-22 13:37 . 2008-02-22 13:37 2,176 –a—— C:\WINSETUP\system32\ssdt.sys
2008-02-22 13:37 . 2008-02-22 13:37 2,176 –a—— C:\WINSETUP\system32\kavshell.sys
2008-02-22 13:37 . 2008-02-24 00:30 1,860 –a—— C:\WINSETUP\system32\sufost.ini
2008-02-22 13:37 . 2008-02-22 13:37 26 –a—— C:\WINSETUP\system32\discard.ini
2008-02-22 13:36 . 2008-02-22 13:36 36,129 —hs—- C:\WINSETUP\system32\Mousie.exe
2008-02-22 13:36 . 2008-02-22 13:36 36,129 —hs—- C:\WINSETUP\MicroSoft.pif
2008-02-22 13:36 . 2008-02-22 13:36 212 –a—— C:\WINSETUP\MicroSoft.vbs
2008-02-03 14:41 . 2008-02-03 15:04 d——– C:\Program Files\g3BlindTimer
2008-02-03 14:40 . 2008-02-03 14:40 d——– C:\WINSETUP\speech

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-05-17 12:45 ——— d–h–w C:\Program Files\InstallShield Installation Information
2017-05-17 12:45 ——— d—–w C:\Program Files\Common Files\InstallShield
2017-05-17 12:00 32,768 –sha-w C:\VIDEOROM.BIN
2017-05-17 11:58 ——— d—–w C:\Program Files\DirectX
2017-05-17 11:57 266 –sh–w C:\Program Files\desktop.ini
2017-05-17 11:57 11,079 —ha-w C:\Program Files\folder.htt
2008-02-24 08:44 ——— d—–w C:\Program Files\Morpheus
2008-02-23 08:30 55,296 —-a-w C:\Program Files\ver.txt
2008-02-22 21:47 141,312 —-a-w C:\WINSETUP\inf\msnetfc.exe
2008-01-22 06:23 ——— d—–w C:\Program Files\iTunes
2008-01-22 06:23 ——— d—–w C:\Program Files\iPod
2008-01-22 06:19 ——— d—–w C:\Program Files\QuickTime
2008-01-12 00:13 ——— d—–w C:\Program Files\Common Files\Adobe
2008-01-07 03:35 ——— d—–w C:\Program Files\Texas Hold 'em
2008-01-07 03:35 ——— d—–w C:\Program Files\BFG
2007-12-31 10:35 ——— d—–w C:\Program Files\Microsoft Plus!
2007-12-27 10:42 ——— d—–w C:\Documents and Settings\Home\Application Data\Image Zone Express
2007-12-27 10:22 ——— d—–w C:\Documents and Settings\Home\Application Data\Printer Info Cache
2007-12-27 08:23 ——— d—–w C:\Documents and Settings\Home\Application Data\HP
2007-12-04 08:42 935,306 —-a-w C:\WINSETUP\system32\Classy Christmas.scr
.

——- Sigcheck ——-

09eb23a4567bdd56d9580a059e616e23 C:\WINSETUP\system32\drivers\tcpip.sys
—-a-w 359,040 2004-08-26 17:42:00 C:\WINSETUP\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-10 19:06 40048]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 21:52 49152]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]

C:\Documents and Settings\All Users.WINSETUP\Start Menu\Programs\Startup\
Hotsync.lnk - C:\Program Files\Palm\Hotsync.exe [2004-06-09 14:27:34 471040]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 21:40:10 210520]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"Mousie"= C:\WINSETUP\system32\Mousie.exe

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{ab0ef373-3503-4a22-ab21-8eafb94f3df5}"= C:\WINSETUP\system32\NNNNNN1029.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\BITS]
C:\WINSETUP\System32\Systen.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360rpt.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360Safe.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360tray.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\adam.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AgentSvr.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\appdllman.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AppSvc32.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\auto.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AutoRun.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\autoruns.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgrssvc.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AvMonitor.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avp.com]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avp.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\CCenter.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ccSvcHst.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\cross.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Discovery.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\FileDsty.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\FTCleanerShell.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\guangd.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\HijackThis.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\IceSword.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iparmo.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Iparmor.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\isPwdSvc.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kabaload.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KaScrScn.SCR]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KASMain.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KASTask.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAV32.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVDX.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVPFW.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVSetup.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVStart.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kernelwind32.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KISLnchr.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KMailMon.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KMFilter.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPFW32.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPFW32X.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPFWSvc.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KRegEx.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KRepair.COM]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KsLoader.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVCenter.kxp]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvDetect.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvfwMcl.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVMonXP.kxp]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVMonXP_1.kxp]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvol.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvolself.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvReport.kxp]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVSrvXP.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVStub.kxp]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvupload.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvwsc.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvXP.kxp]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatch.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatch9x.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatchX.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\loaddll.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\logogo.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\MagicSet.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mcconsol.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mmqczj.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mmsk.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NAVSetup.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32krn.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32kui.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\PFW.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\PFWLiveUpdate.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\QHSET.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Ras.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Rav.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavMon.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavMonD.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavStub.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavTask.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RegClean.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\regedit.Exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\regedit32.Exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwcfg.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RfwMain.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwProxy.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwsrv.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RsAgent.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Rsaupd.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\runiep.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\safelive.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\scan32.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SDGames.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\servet.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\shcfg32.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SmartUp.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\sos.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SREng.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\symlcsvc.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SysSafe.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\taskmgr.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TNT.Exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TrojanDetector.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Trojanwall.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TrojDie.kxp]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TxoMoU.Exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UFO.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UIHost.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxAgent.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxAttachment.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxCfg.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxFwHlp.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxPol.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UpLive.EXE]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\WoptiClean.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Wsyscheck.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\XP.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\zxsweep.exe]
Debugger=C:\WINSETUP\system32\Mousie.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINSETUP\mrofinu572.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Morpheus\\Morpheus.exe"=
"C:\\Program Files\\CA\\eTrust Antivirus\\Shellscn.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\CA\\eTrust Antivirus\\Realmon.exe"=

R0 rzr8w536j;rzr8w536;C:\WINSETUP\system32\DRIVERS\rzr8w536j.sys [2004-08-04 07:00]
R2 COMROMLoader64;DCOM Service Process Manager;C:\WINSETUP\system32\svchost.exe [2004-08-04 07:00]
R2 Event;Event;C:\WINSETUP\system32\svchost.exe [2004-08-04 07:00]
R2 mjb1sgtjvt;mjb1sgtjvt;C:\WINSETUP\system32\drivers\mjb1sgtjvt.sys [2004-08-04 07:00]
R2 yikqacvm;yikqacvm;C:\WINSETUP\system32\drivers\cexysu.SYS [2004-08-04 07:00]
S3 kavshell;kavshell;C:\WINSETUP\system32\kavshell.sys [2008-02-22 13:37]
S3 Ndisprot;Network Monitor Protocol Driver;C:\WINSETUP\system32\DRIVERS\winsys.sys [2008-02-22 22:09]
S3 RESSDT;RESSDT;C:\WINSETUP\system32\ssdt.sys [2008-02-22 13:37]
S3 SpoolsvsDrv;SpoolsvsDrv;C:\WINSETUP\system32\Spools.sys []
S4 Alibaba;Alibaba;C:\WINSETUP\system32\svchost.exe [2004-08-04 07:00]
S4 Nonprotect;Nonprotect;C:\WINDOWS\system32\serv.exe []
S4 Spoolsvs;Spool Srv;C:\WINSETUP\system32\Spools.exe [2004-08-04 07:00]
S4 WinCOM;COM+ Windows System;C:\WINSETUP\system32\wincom.exe [2008-02-22 22:08]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Event REG_MULTI_SZ Event
Alibaba REG_MULTI_SZ Alibaba

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
COMROMLoader64

.
Contents of the 'Scheduled Tasks' folder
"2008-02-24 07:41:05 C:\WINSETUP\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-25 00:15:57
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Mousie = C:\WINSETUP\system32\Mousie.exe???)?????????????C:\WINSETUP\system32\Mousie.exe?????Q??????? ???HP Deskjet F4100 series - Status??)????????? ???HP Deskjet F4100 series - Status??)????????? ???HP Deskjet F4100 series - Status??)????????? ???HP Deskjet F410

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINSETUP\system32\winlogon.exe
-> c:\winsetup\system32\qsrfcq.dll
.
Completion time: 2008-02-25 0:16:56
ComboFix-quarantined-files.txt 2008-02-25 08:16:39
ComboFix2.txt 2008-02-25 07:55:42


SmitFraudFix v2.274

Scan done at 0:56:03.62, Sat 02/23/2008
Run from D:\Backups\Dell\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix.exe by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» DNS



»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End



any help would be greatly appreciated. i'll probably check this tomorrow around 1130pm pacific time. thanks!!!