This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Cant get rid of malware

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:pullhair:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:26:37 AM, on 2/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2080110
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2080110
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/&s=5nMMnMSypzYU763wFjyTdarNLP0
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {98828DED-A591-462F-83BA-D2F62A68B8B8} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BM63b544b5] Rundll32.exe "C:\WINDOWS\system32\vxkiisva.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{653D37BF-2A4E-4A59-8723-B742E0CDB114}: NameServer = 69.78.96.14 66.174.95.44
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE (file missing)

–
End of file - 4935 bytes


Fairly new laptop and right away it seems to have issues. I would like to use this laptop for 2 purposes: 1) Im going back to school so I need a mobile word processor, and mobile access to the internet. 2) Im going back to school and need a distraction like World of Warcraft. =D
I know that this has at least one issue: VIrtumonde - I cant seem to kill this thing. I have tried getting specific 'VundoFix' programs to clean it up, but it just wont die. I believe that this program keeps downloading other malware, because i ill run spybot, clean everything, then later ill find virtumonde, then run it again and a bunch of stuff shows up again. Also, i would love to get rid of anything that is not absolutely mandentory. i turned off alot of the startup programs but dont know which is what. anything that isnt amazingly awesome needs to be canned. please help, it has gotten really bad and causes redirects and popups to the point where IE crashes and i have to start over from homepage. thanks for everything, yall rock.
Hello

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Please, never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
Ok, here is the ComboFix log:


ComboFix 08-03-01 - Wilke 2008-02-29 16:22:22.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1601 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Helper
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\agpodhkx.dll
C:\WINDOWS\system32\aiuwsevu.dll
C:\WINDOWS\system32\bmcmvehn.dll
C:\WINDOWS\system32\bmulqpbc.dll
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\btuqvsht.dll
C:\WINDOWS\system32\cbpqlumb.ini
C:\WINDOWS\system32\cfkwnxxo.ini
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\egjlm.ini
C:\WINDOWS\system32\egjlm.ini2
C:\WINDOWS\system32\etbdvbby.dll
C:\WINDOWS\system32\exotbqqr.dll
C:\WINDOWS\system32\fjltnygj.ini
C:\WINDOWS\system32\fshdkshb.dll
C:\WINDOWS\system32\hfqduxws.dll
C:\WINDOWS\system32\hyrqvggu.dll
C:\WINDOWS\system32\jgyntljf.dll
C:\WINDOWS\system32\jpxgbhxb.dll
C:\WINDOWS\system32\jtkkecit.ini
C:\WINDOWS\system32\lurpwqiv.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mljge.dll
C:\WINDOWS\system32\mljge.exe
C:\WINDOWS\system32\oxxnwkfc.dll
C:\WINDOWS\system32\pynckqot.dll
C:\WINDOWS\system32\RCX11.tmp
C:\WINDOWS\system32\RCX12.tmp
C:\WINDOWS\system32\RCX13.tmp
C:\WINDOWS\system32\RCXE.tmp
C:\WINDOWS\system32\RCXF.tmp
C:\WINDOWS\system32\tcwjvyss.dll
C:\WINDOWS\system32\thsvqutb.ini
C:\WINDOWS\system32\ticekktj.dll
C:\WINDOWS\system32\tyqwtefu.ini
C:\WINDOWS\system32\ufetwqyt.dll
C:\WINDOWS\system32\uggvqryh.ini
C:\WINDOWS\system32\vxkiisva.dll
C:\WINDOWS\system32\wacissqx.dll
C:\WINDOWS\system32\xbabwbkb.dll
C:\WINDOWS\system32\xkhdopga.ini
C:\WINDOWS\system32\ybbvdbte.ini
C:\WINDOWS\system32\yybeg.ini
C:\WINDOWS\system32\yybeg.ini2

.
((((((((((((((((((((((((( Files Created from 2008-02-01 to 2008-03-01 )))))))))))))))))))))))))))))))
.

2008-02-28 16:42 . 2008-02-28 16:42 d——– C:\VundoFix Backups
2008-02-28 16:24 . 2008-02-28 16:52 d——– C:\Program Files\HJT
2008-02-28 13:54 . 2008-02-28 13:54 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-27 13:17 . 2008-03-01 16:22 21 –a—— C:\WINDOWS\pskt.ini
2008-02-27 10:36 . 2008-02-27 10:36 d——– C:\Documents and Settings\Wilke\Application Data\MSNInstaller
2008-02-27 10:04 . 2008-02-27 10:04 d——– C:\Documents and Settings\Wilke\Application Data\Apple Computer
2008-02-26 21:20 . 2008-03-01 16:22 99,434 –a—— C:\WINDOWS\BM63b544b5.xml
2008-02-21 16:39 . 2008-02-21 16:39 d——– C:\Documents and Settings\All Users\Application Data\iWin Games
2008-02-21 16:38 . 2008-02-21 16:38 d——– C:\Program Files\iWin.com Games
2008-02-21 16:38 . 2008-02-21 16:38 d——– C:\Program Files\iWin Games
2008-02-19 19:45 . 2008-02-19 19:45 334,848 –a—— C:\WINDOWS\system32\cuxnvprs.zwo
2008-02-19 13:30 . 2008-02-19 13:30 d——– C:\Program Files\Apple Software Update
2008-02-19 13:30 . 2008-02-27 10:59 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-19 13:30 . 2008-02-19 13:30 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-02-18 18:44 . 2008-02-18 18:38 691,545 –a—— C:\WINDOWS\unins000.exe
2008-02-18 18:44 . 2008-02-18 18:44 3,442 –a—— C:\WINDOWS\unins000.dat
2008-02-04 11:10 . 2004-08-03 23:01 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2008-02-04 11:10 . 2004-08-03 23:01 25,856 –a—— C:\WINDOWS\system32\dllcache\usbprint.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-29 14:59 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-28 17:09 1,686 —-a-w C:\Documents and Settings\Wilke\Application Data\wklnhst.dat
2008-02-19 00:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-14 16:19 ——— d—–w C:\Documents and Settings\Wilke\Application Data\U3
2008-02-02 00:13 ——— d—–w C:\Program Files\World of Warcraft
2008-01-20 15:23 ——— d—–w C:\Program Files\CDKnet
2008-01-18 21:04 ——— d—–w C:\Program Files\Docking Station
2008-01-18 19:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-01-18 16:01 ——— d—–w C:\Program Files\Trend Micro
2008-01-18 03:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-18 03:08 ——— d—–w C:\Program Files\Lavasoft
2008-01-18 02:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-01-18 01:39 2,048 —-a-w C:\WINDOWS\system32\drivers\FABB7A7E-D0F3-4B35-A167-ACD19F5376C9.cxv
2008-01-17 23:44 2,048 —-a-w C:\WINDOWS\system32\drivers\F0161235-D5E8-4013-A5B5-A1D263A0043A.cxv
2008-01-17 22:36 5,120 —-a-w C:\WINDOWS\system32\drivers\6DD98783-C887-4DC9-8CEF-C7D431AE3495.cxv
2008-01-17 22:00 ——— d—–w C:\Program Files\Enigma Software Group
2008-01-17 20:26 ——— d—–w C:\Program Files\CyberLink
2008-01-17 20:21 ——— d—–w C:\Program Files\Starcraft
2008-01-17 18:32 ——— d—–w C:\Program Files\FableTLCMod
2008-01-16 16:26 ——— d—–w C:\Program Files\MSXML 4.0
2008-01-15 23:35 ——— d—–w C:\Documents and Settings\Wilke\Application Data\Smith Micro
2008-01-15 23:20 ——— d—–w C:\Program Files\Verizon Wireless
2008-01-15 23:20 ——— d—–w C:\Program Files\PANTECH
2008-01-15 21:41 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-15 21:23 ——— d—–w C:\Program Files\Google
2008-01-15 21:06 ——— d—–w C:\Program Files\Common Files\Intuit
2008-01-15 21:06 ——— d—–w C:\Program Files\Common Files\AnswerWorks 4.0
2008-01-15 21:05 ——— d—–w C:\Program Files\Intuit
2008-01-15 21:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Intuit
2008-01-15 21:03 ——— d—–w C:\Program Files\Common Files\SWF Studio
2008-01-15 17:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Dell
2008-01-15 15:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\Support.com
2008-01-15 15:46 ——— d—–w C:\Program Files\Common Files\Motive
2008-01-15 15:46 ——— d—–w C:\Documents and Settings\All Users\Application Data\Motive
2008-01-14 22:01 ——— d—–w C:\Documents and Settings\Wilke\Application Data\CyberLink
2008-01-14 20:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-01-14 20:09 ——— d—–w C:\Documents and Settings\Wilke\Application Data\Template
2008-01-14 19:56 126,976 —-a-w C:\WINDOWS\War3Unin.exe
2008-01-14 19:56 ——— d—–w C:\Program Files\Warcraft III
2008-01-14 19:43 94,208 —-a-w C:\WINDOWS\ScUnin.exe
2008-01-14 18:50 ——— d—–w C:\Program Files\Microsoft Games
2008-01-14 17:58 ——— d—–w C:\Program Files\Common Files\Blizzard Entertainment
2008-01-14 17:08 ——— d—–w C:\Documents and Settings\Wilke\Application Data\Dell
2008-01-10 23:34 ——— d—–w C:\Documents and Settings\Wilke\Application Data\Roxio
2008-01-10 23:34 ——— d—–w C:\Documents and Settings\LocalService\Application Data\Roxio
2008-01-10 23:34 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Roxio
2008-01-10 23:32 ——— d—–w C:\Program Files\Microsoft Works
2008-01-10 23:31 ——— d—–w C:\Program Files\MSECache
2008-01-10 23:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-10 23:29 ——— d—–w C:\Program Files\Dell Support Center
2008-01-10 23:29 ——— d—–w C:\Program Files\Dell
2008-01-10 23:29 ——— d—–w C:\Program Files\Common Files\supportsoft
2008-01-10 23:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-01-10 23:28 ——— d—–w C:\Program Files\Dell Network Assistant
2008-01-10 23:28 ——— d—–w C:\Program Files\Common Files\Adobe
2008-01-10 23:28 ——— d—–w C:\Documents and Settings\All Users\Application Data\SingleClick Systems
2008-01-10 23:26 ——— d—–w C:\Program Files\Roxio
2008-01-10 23:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Roxio
2008-01-10 23:25 ——— d—–w C:\Program Files\Common Files\Sonic Shared
2008-01-10 23:24 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-01-10 23:23 ——— d—–w C:\Program Files\Common Files\SureThing Shared
2008-01-10 23:23 ——— d—–w C:\Program Files\Common Files\Roxio Shared
2008-01-10 23:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sonic
2008-01-10 23:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-01-10 23:22 ——— d—–w C:\Program Files\Sigmatel
2008-01-10 23:20 ——— d—–w C:\Program Files\NetWaiting
2008-01-10 23:20 ——— d—–w C:\Program Files\Digital Line Detect
2008-01-10 23:20 ——— d—–w C:\Program Files\CONEXANT
2008-01-10 23:20 ——— d—–w C:\Documents and Settings\Wilke\Application Data\InstallShield
2008-01-10 23:20 ——— d—–w C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-01-10 23:19 ——— d—–w C:\Program Files\Modem Diagnostic Tool
2008-01-10 23:17 ——— d—–w C:\Program Files\Java
2008-01-10 23:17 ——— d—–w C:\Program Files\Common Files\Java
2008-01-10 23:15 ——— d—–w C:\Program Files\MSXML 6.0
2008-01-10 23:04 ——— d—–w C:\Program Files\Synaptics
2008-01-10 22:58 6,761 —-a-w C:\WINDOWS\system32\drivers\1028_Dell_VOS_1500.mrk
.
—-a-w			17,920 2008-01-17 22:09:32  C:\dell\E-Center\EULALauncher .exe
—-a-w			40,048 2008-02-29 15:00:01  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w			81,920 2008-01-17 22:09:30  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		   221,184 2008-01-17 22:09:28  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
—-a-w		   221,184 2008-01-17 22:09:29  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9 .exe
—-a-w		   189,736 2008-01-17 22:09:37  C:\Program Files\Dell\MediaDirect\PCMService .exe
—-a-w		   202,544 2008-01-17 22:09:43  C:\Program Files\Dell Support Center\bin\sprtcmd .exe
—-a-w			16,384 2008-01-17 22:09:34  C:\Program Files\Dell Support Center\gs_agent\custom\dsca .exe
—-a-w			68,856 2008-01-17 22:09:44  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w			36,975 2008-01-17 22:09:27  C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe
—-a-w		 1,116,920 2008-01-17 22:09:32  C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc .exe
—-a-w		 2,097,488 2008-02-29 15:00:06  C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
—-a-w		   851,968 2008-02-29 15:00:03  C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
—-a-w		   169,984 2008-02-29 15:05:09  C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
—-a-w			15,360 2008-02-29 19:23:13  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   282,624 2008-01-17 22:09:27  C:\WINDOWS\system32\KADxMain .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-06 16:34 8429568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnolji]
pmnolji.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-02-29 09:59 379392 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM63b544b5]
C:\WINDOWS\system32\vxkiisva.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
C:\WINDOWS\system32\WLTRAY.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 06:00 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\mljge.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2007-06-06 16:34 8429568 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVHotkey]
–a—— 2007-06-06 16:34 67584 C:\WINDOWS\system32\nvhotkey.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-06-06 16:34 81920 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2007-06-06 16:35 1626112 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
C:\Program Files\Dell\MediaDirect\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
–a—— 2007-06-06 16:28 405504 C:\WINDOWS\stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
–a—— 2008-02-29 09:59 2439680 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
–a—— 2008-02-29 09:59 1222144 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.12.6546-enUS-downloader.exe"=
"C:\\Program Files\\Intuit\\QuickBooks 2006\\QBDBMgrN.exe"=
"C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iWin Games\\iWinGames.exe"=
"C:\\Program Files\\iWin Games\\WebUpdater.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC

R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 11:35]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-10-09 19:56]
R3 DXEC02;DXEC02;C:\WINDOWS\system32\drivers\dxec02.sys [2006-11-02 13:31]
S3 PTDMBus;PANTECH USB Modem Composite Device Driver ;C:\WINDOWS\system32\DRIVERS\PTDMBus.sys [2007-08-17 20:56]
S3 PTDMMdm;PANTECH USB Modem Drivers ;C:\WINDOWS\system32\DRIVERS\PTDMMdm.sys [2007-08-17 20:56]
S3 PTDMVsp;PANTECH USB Modem Serial Port ;C:\WINDOWS\system32\DRIVERS\PTDMVsp.sys [2007-08-17 20:56]
S3 PTDMWWAN;PANTECH USB Modem WWAN Driver;C:\WINDOWS\system32\DRIVERS\PTDMWWAN.sys [2007-08-17 20:56]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 06:00]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-19 18:30:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-01 16:25:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2008-03-01 16:27:22 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-01 21:27:19
.
2008-02-17 02:57:35 — E O F —




And here is the new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:33:05 PM, on 3/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2080110
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/&s=5nMMnMSypzYU763wFjyTdarNLP0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {98828DED-A591-462F-83BA-D2F62A68B8B8} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{653D37BF-2A4E-4A59-8723-B742E0CDB114}: NameServer = 69.78.96.14 66.174.95.44
O20 - Winlogon Notify: pmnolji - pmnolji.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE (file missing)

–
End of file - 5237 bytes




Thank you for your amazingly fast response =D
Hello

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O3 - Toolbar: (no name) - {98828DED-A591-462F-83BA-D2F62A68B8B8} - (no file)
O20 - Winlogon Notify: pmnolji - pmnolji.dll (file missing)


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.


1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\vxkiisva.dll
C:\WINDOWS\system32\mljge.exe

KillAll::

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM63b544b5]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]

RenV::
—-a-w			17,920 2008-01-17 22:09:32  C:\dell\E-Center\EULALauncher .exe
—-a-w			40,048 2008-02-29 15:00:01  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w			81,920 2008-01-17 22:09:30  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		   221,184 2008-01-17 22:09:28  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
—-a-w		   221,184 2008-01-17 22:09:29  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9 .exe
—-a-w		   189,736 2008-01-17 22:09:37  C:\Program Files\Dell\MediaDirect\PCMService .exe
—-a-w		   202,544 2008-01-17 22:09:43  C:\Program Files\Dell Support Center\bin\sprtcmd .exe
—-a-w			16,384 2008-01-17 22:09:34  C:\Program Files\Dell Support Center\gs_agent\custom\dsca .exe
—-a-w			68,856 2008-01-17 22:09:44  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w			36,975 2008-01-17 22:09:27  C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe
—-a-w		 1,116,920 2008-01-17 22:09:32  C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc .exe
—-a-w		 2,097,488 2008-02-29 15:00:06  C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
—-a-w		   851,968 2008-02-29 15:00:03  C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
—-a-w		   169,984 2008-02-29 15:05:09  C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
—-a-w			15,360 2008-02-29 19:23:13  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   282,624 2008-01-17 22:09:27  C:\WINDOWS\system32\KADxMain .exe

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall




Reboot and post a new HijackThis log
ComboFix log:


ComboFix 08-03-01 - Wilke 2008-03-01 20:32:21.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1667 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Wilke\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-02-02 to 2008-03-02 )))))))))))))))))))))))))))))))
.

2008-02-28 16:42 . 2008-02-28 16:42 d——– C:\VundoFix Backups
2008-02-28 16:24 . 2008-02-28 16:52 d——– C:\Program Files\HJT
2008-02-28 13:54 . 2008-02-28 13:54 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-27 13:17 . 2008-03-01 16:22 21 –a—— C:\WINDOWS\pskt.ini
2008-02-27 10:36 . 2008-02-27 10:36 d——– C:\Documents and Settings\Wilke\Application Data\MSNInstaller
2008-02-27 10:04 . 2008-02-27 10:04 d——– C:\Documents and Settings\Wilke\Application Data\Apple Computer
2008-02-26 21:20 . 2008-03-01 16:22 99,434 –a—— C:\WINDOWS\BM63b544b5.xml
2008-02-21 16:39 . 2008-02-21 16:39 d——– C:\Documents and Settings\All Users\Application Data\iWin Games
2008-02-21 16:38 . 2008-02-21 16:38 d——– C:\Program Files\iWin.com Games
2008-02-21 16:38 . 2008-02-21 16:38 d——– C:\Program Files\iWin Games
2008-02-19 19:45 . 2008-02-19 19:45 334,848 –a—— C:\WINDOWS\system32\cuxnvprs.zwo
2008-02-19 13:30 . 2008-02-19 13:30 d——– C:\Program Files\Apple Software Update
2008-02-19 13:30 . 2008-02-27 10:59 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-19 13:30 . 2008-02-19 13:30 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-02-18 18:44 . 2008-02-18 18:38 691,545 –a—— C:\WINDOWS\unins000.exe
2008-02-18 18:44 . 2008-02-18 18:44 3,442 –a—— C:\WINDOWS\unins000.dat
2008-02-04 11:10 . 2004-08-03 23:01 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2008-02-04 11:10 . 2004-08-03 23:01 25,856 –a—— C:\WINDOWS\system32\dllcache\usbprint.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-29 19:23 15,360 —-a-w C:\WINDOWS\system32\ctfmon .exe
2008-02-29 15:05 169,984 —-a-w C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
2008-02-29 14:59 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-28 17:09 1,686 —-a-w C:\Documents and Settings\Wilke\Application Data\wklnhst.dat
2008-02-19 00:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-14 16:19 ——— d—–w C:\Documents and Settings\Wilke\Application Data\U3
2008-02-02 00:13 ——— d—–w C:\Program Files\World of Warcraft
2008-01-20 15:23 ——— d—–w C:\Program Files\CDKnet
2008-01-18 21:04 ——— d—–w C:\Program Files\Docking Station
2008-01-18 19:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-01-18 16:01 ——— d—–w C:\Program Files\Trend Micro
2008-01-18 03:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-18 03:08 ——— d—–w C:\Program Files\Lavasoft
2008-01-18 02:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-01-18 01:39 2,048 —-a-w C:\WINDOWS\system32\drivers\FABB7A7E-D0F3-4B35-A167-ACD19F5376C9.cxv
2008-01-17 23:44 2,048 —-a-w C:\WINDOWS\system32\drivers\F0161235-D5E8-4013-A5B5-A1D263A0043A.cxv
2008-01-17 22:36 5,120 —-a-w C:\WINDOWS\system32\drivers\6DD98783-C887-4DC9-8CEF-C7D431AE3495.cxv
2008-01-17 22:09 282,624 —-a-w C:\WINDOWS\system32\KADxMain .exe
2008-01-17 22:00 ——— d—–w C:\Program Files\Enigma Software Group
2008-01-17 20:26 ——— d—–w C:\Program Files\CyberLink
2008-01-17 20:21 ——— d—–w C:\Program Files\Starcraft
2008-01-17 18:32 ——— d—–w C:\Program Files\FableTLCMod
2008-01-17 17:43 1,700,352 —-a-w C:\WINDOWS\system32\gdiplus.dll
2008-01-16 19:22 6,094,848 —-a-w C:\WINDOWS\system32\Skyrocket.scr
2008-01-16 19:22 483,328 —-a-w C:\WINDOWS\system32\Helios.scr
2008-01-16 19:22 450,560 —-a-w C:\WINDOWS\system32\Euphoria.scr
2008-01-16 19:22 274,432 —-a-w C:\WINDOWS\system32\Cyclone.scr
2008-01-16 19:22 249,856 —-a-w C:\WINDOWS\system32\Flocks.scr
2008-01-16 19:22 245,760 —-a-w C:\WINDOWS\system32\Flux.scr
2008-01-16 19:22 237,568 —-a-w C:\WINDOWS\system32\SolarWinds.scr
2008-01-16 19:22 237,568 —-a-w C:\WINDOWS\system32\FieldLines.scr
2008-01-16 19:22 229,376 —-a-w C:\WINDOWS\system32\Plasma.scr
2008-01-16 19:22 1,908,736 —-a-w C:\WINDOWS\system32\Lattice.scr
2008-01-16 16:26 ——— d—–w C:\Program Files\MSXML 4.0
2008-01-15 23:35 ——— d—–w C:\Documents and Settings\Wilke\Application Data\Smith Micro
2008-01-15 23:20 ——— d—–w C:\Program Files\Verizon Wireless
2008-01-15 23:20 ——— d—–w C:\Program Files\PANTECH
2008-01-15 21:41 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-15 21:23 ——— d—–w C:\Program Files\Google
2008-01-15 21:06 ——— d—–w C:\Program Files\Common Files\Intuit
2008-01-15 21:06 ——— d—–w C:\Program Files\Common Files\AnswerWorks 4.0
2008-01-15 21:05 ——— d—–w C:\Program Files\Intuit
2008-01-15 21:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Intuit
2008-01-15 21:03 ——— d—–w C:\Program Files\Common Files\SWF Studio
2008-01-15 17:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Dell
2008-01-15 15:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\Support.com
2008-01-15 15:46 ——— d—–w C:\Program Files\Common Files\Motive
2008-01-15 15:46 ——— d—–w C:\Documents and Settings\All Users\Application Data\Motive
2008-01-14 22:01 ——— d—–w C:\Documents and Settings\Wilke\Application Data\CyberLink
2008-01-14 20:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-01-14 20:09 ——— d—–w C:\Documents and Settings\Wilke\Application Data\Template
2008-01-14 19:56 126,976 —-a-w C:\WINDOWS\War3Unin.exe
2008-01-14 19:56 ——— d—–w C:\Program Files\Warcraft III
2008-01-14 19:43 94,208 —-a-w C:\WINDOWS\ScUnin.exe
2008-01-14 18:50 ——— d—–w C:\Program Files\Microsoft Games
2008-01-14 17:58 ——— d—–w C:\Program Files\Common Files\Blizzard Entertainment
2008-01-14 17:08 ——— d—–w C:\Documents and Settings\Wilke\Application Data\Dell
2008-01-11 05:53 44,544 —-a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-10 23:34 ——— d—–w C:\Documents and Settings\Wilke\Application Data\Roxio
2008-01-10 23:34 ——— d—–w C:\Documents and Settings\LocalService\Application Data\Roxio
2008-01-10 23:34 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Roxio
2008-01-10 23:32 ——— d—–w C:\Program Files\Microsoft Works
2008-01-10 23:31 ——— d—–w C:\Program Files\MSECache
2008-01-10 23:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-10 23:29 ——— d—–w C:\Program Files\Dell Support Center
2008-01-10 23:29 ——— d—–w C:\Program Files\Dell
2008-01-10 23:29 ——— d—–w C:\Program Files\Common Files\supportsoft
2008-01-10 23:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-01-10 23:28 ——— d—–w C:\Program Files\Dell Network Assistant
2008-01-10 23:28 ——— d—–w C:\Program Files\Common Files\Adobe
2008-01-10 23:28 ——— d—–w C:\Documents and Settings\All Users\Application Data\SingleClick Systems
2008-01-10 23:26 ——— d—–w C:\Program Files\Roxio
2008-01-10 23:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Roxio
2008-01-10 23:25 ——— d—–w C:\Program Files\Common Files\Sonic Shared
2008-01-10 23:24 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-01-10 23:23 ——— d—–w C:\Program Files\Common Files\SureThing Shared
2008-01-10 23:23 ——— d—–w C:\Program Files\Common Files\Roxio Shared
2008-01-10 23:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sonic
2008-01-10 23:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-01-10 23:22 ——— d—–w C:\Program Files\Sigmatel
2008-01-10 23:20 ——— d—–w C:\Program Files\NetWaiting
2008-01-10 23:20 ——— d—–w C:\Program Files\Digital Line Detect
2008-01-10 23:20 ——— d—–w C:\Program Files\CONEXANT
2008-01-10 23:20 ——— d—–w C:\Documents and Settings\Wilke\Application Data\InstallShield
2008-01-10 23:20 ——— d—–w C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-01-10 23:19 ——— d—–w C:\Program Files\Modem Diagnostic Tool
2008-01-10 23:17 ——— d—–w C:\Program Files\Java
2008-01-10 23:17 ——— d—–w C:\Program Files\Common Files\Java
2008-01-10 23:15 ——— d—–w C:\Program Files\MSXML 6.0
2008-01-10 23:04 ——— d—–w C:\Program Files\Synaptics
2008-01-10 22:58 6,761 —-a-w C:\WINDOWS\system32\drivers\1028_Dell_VOS_1500.mrk
2007-12-19 23:01 347,136 —-a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 ——w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-14 16:32 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-08 05:21 3,592,192 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 11:01 625,664 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-12-06 11:00 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-06 04:59 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\system32\oleaut32.dll
.
—-a-w			17,920 2008-01-17 22:09:32  C:\dell\E-Center\EULALauncher .exe
—-a-w			40,048 2008-02-29 15:00:01  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w			81,920 2008-01-17 22:09:30  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		   221,184 2008-01-17 22:09:28  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
—-a-w		   221,184 2008-01-17 22:09:29  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9 .exe
—-a-w		   189,736 2008-01-17 22:09:37  C:\Program Files\Dell\MediaDirect\PCMService .exe
—-a-w		   202,544 2008-01-17 22:09:43  C:\Program Files\Dell Support Center\bin\sprtcmd .exe
—-a-w			16,384 2008-01-17 22:09:34  C:\Program Files\Dell Support Center\gs_agent\custom\dsca .exe
—-a-w			68,856 2008-01-17 22:09:44  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w			36,975 2008-01-17 22:09:27  C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe
—-a-w		 1,116,920 2008-01-17 22:09:32  C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc .exe
—-a-w		 2,097,488 2008-02-29 15:00:06  C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
—-a-w		   851,968 2008-02-29 15:00:03  C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
—-a-w		   169,984 2008-02-29 15:05:09  C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
—-a-w			15,360 2008-02-29 19:23:13  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   282,624 2008-01-17 22:09:27  C:\WINDOWS\system32\KADxMain .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-06 16:34 8429568]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-02-29 09:59 379392 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM63b544b5]
C:\WINDOWS\system32\vxkiisva.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
C:\WINDOWS\system32\WLTRAY.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 06:00 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\mljge.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2007-06-06 16:34 8429568 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVHotkey]
–a—— 2007-06-06 16:34 67584 C:\WINDOWS\system32\nvhotkey.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-06-06 16:34 81920 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2007-06-06 16:35 1626112 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
C:\Program Files\Dell\MediaDirect\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
–a—— 2007-06-06 16:28 405504 C:\WINDOWS\stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
–a—— 2008-02-29 09:59 2439680 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
–a—— 2008-02-29 09:59 1222144 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.12.6546-enUS-downloader.exe"=
"C:\\Program Files\\Intuit\\QuickBooks 2006\\QBDBMgrN.exe"=
"C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iWin Games\\iWinGames.exe"=
"C:\\Program Files\\iWin Games\\WebUpdater.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC

R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 11:35]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-10-09 19:56]
R3 DXEC02;DXEC02;C:\WINDOWS\system32\drivers\dxec02.sys [2006-11-02 13:31]
S3 PTDMBus;PANTECH USB Modem Composite Device Driver ;C:\WINDOWS\system32\DRIVERS\PTDMBus.sys [2007-08-17 20:56]
S3 PTDMMdm;PANTECH USB Modem Drivers ;C:\WINDOWS\system32\DRIVERS\PTDMMdm.sys [2007-08-17 20:56]
S3 PTDMVsp;PANTECH USB Modem Serial Port ;C:\WINDOWS\system32\DRIVERS\PTDMVsp.sys [2007-08-17 20:56]
S3 PTDMWWAN;PANTECH USB Modem WWAN Driver;C:\WINDOWS\system32\DRIVERS\PTDMWWAN.sys [2007-08-17 20:56]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 06:00]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-19 18:30:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-01 20:32:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-01 20:33:15
ComboFix-quarantined-files.txt 2008-03-02 01:33:14
ComboFix2.txt 2008-03-01 21:27:23
.
2008-02-17 02:57:35 — E O F —






HijackThis log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:37:05 PM, on 3/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2080110
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/&s=5nMMnMSypzYU763wFjyTdarNLP0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE (file missing)

–
End of file - 4795 bytes



Again, thanks for the help. I hope this fixes everything =D
Hello

  • Download RenV.exe by sUBs to your desktop
  • Double click on it to run it
  • It will search your system drive looking for any modified .exe file and will produce a log for you.
  • Please drag this log into RenV.exe and post the resulting log
Ok, here is the file that got saved to desktop:

Ran on Sun 03/02/2008 - 11:42:00.31

—-a-w			17,920 2008-01-17 22:09:32  C:\dell\E-Center\EULALauncher .exe
—-a-w			40,048 2008-02-29 15:00:01  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w			81,920 2008-01-17 22:09:30  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		   221,184 2008-01-17 22:09:28  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
—-a-w		   221,184 2008-01-17 22:09:29  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9 .exe
—-a-w		   189,736 2008-01-17 22:09:37  C:\Program Files\Dell\MediaDirect\PCMService .exe
—-a-w		   202,544 2008-01-17 22:09:43  C:\Program Files\Dell Support Center\bin\sprtcmd .exe
—-a-w			16,384 2008-01-17 22:09:34  C:\Program Files\Dell Support Center\gs_agent\custom\dsca .exe
—-a-w			68,856 2008-01-17 22:09:44  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w			36,975 2008-01-17 22:09:27  C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe
—-a-w		 1,116,920 2008-01-17 22:09:32  C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc .exe
—-a-w		 2,097,488 2008-02-29 15:00:06  C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
—-a-w		   851,968 2008-02-29 15:00:03  C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
—-a-w		   169,984 2008-02-29 15:05:09  C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
—-a-w			15,360 2008-02-29 19:23:13  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   282,624 2008-01-17 22:09:27  C:\WINDOWS\system32\KADxMain .exe

 Entries:			   16  (16)
 Directories:			0  Files:			16
 Bytes:		  5,631,095  Blocks:	   11,002




Here is the file that came up after i drug it into the program:

Ran on Sun 03/02/2008 - 11:43:18.26

 Entries:				0  (0)
 Directories:			0  Files:			 0
 Bytes:				  0  Blocks:			0




thanks for the continued help.
here is the latest combofix log:



ComboFix 08-03-01 - Wilke 2008-03-05 13:31:41.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1693 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-02-05 to 2008-03-05 )))))))))))))))))))))))))))))))
.

2008-02-28 16:42 . 2008-02-28 16:42 d——– C:\VundoFix Backups
2008-02-28 16:24 . 2008-02-28 16:52 d——– C:\Program Files\HJT
2008-02-28 13:54 . 2008-02-28 13:54 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-27 13:17 . 2008-03-01 16:22 21 –a—— C:\WINDOWS\pskt.ini
2008-02-27 10:36 . 2008-02-27 10:36 d——– C:\Documents and Settings\Wilke\Application Data\MSNInstaller
2008-02-27 10:04 . 2008-02-27 10:04 d——– C:\Documents and Settings\Wilke\Application Data\Apple Computer
2008-02-26 21:20 . 2008-03-01 16:22 99,434 –a—— C:\WINDOWS\BM63b544b5.xml
2008-02-21 16:39 . 2008-02-21 16:39 d——– C:\Documents and Settings\All Users\Application Data\iWin Games
2008-02-21 16:38 . 2008-02-21 16:38 d——– C:\Program Files\iWin.com Games
2008-02-21 16:38 . 2008-02-21 16:38 d——– C:\Program Files\iWin Games
2008-02-19 19:45 . 2008-02-19 19:45 334,848 –a—— C:\WINDOWS\system32\cuxnvprs.zwo
2008-02-19 13:30 . 2008-02-19 13:30 d——– C:\Program Files\Apple Software Update
2008-02-19 13:30 . 2008-02-27 10:59 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-19 13:30 . 2008-02-19 13:30 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-02-18 18:44 . 2008-02-18 18:38 691,545 –a—— C:\WINDOWS\unins000.exe
2008-02-18 18:44 . 2008-02-18 18:44 3,442 –a—— C:\WINDOWS\unins000.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-02 16:43 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-29 19:23 15,360 —-a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-02-29 19:23 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
2008-02-29 15:05 169,984 —-a-w C:\WINDOWS\system32\dllcache\msconfig.exe
2008-02-29 15:05 169,984 —-a-w C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe
2008-02-28 17:09 1,686 —-a-w C:\Documents and Settings\Wilke\Application Data\wklnhst.dat
2008-02-19 00:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-14 16:19 ——— d—–w C:\Documents and Settings\Wilke\Application Data\U3
2008-02-02 00:13 ——— d—–w C:\Program Files\World of Warcraft
2008-01-20 15:23 ——— d—–w C:\Program Files\CDKnet
2008-01-18 21:04 ——— d—–w C:\Program Files\Docking Station
2008-01-18 19:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-01-18 16:01 ——— d—–w C:\Program Files\Trend Micro
2008-01-18 03:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-18 03:08 ——— d—–w C:\Program Files\Lavasoft
2008-01-18 02:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-01-18 01:39 2,048 —-a-w C:\WINDOWS\system32\drivers\FABB7A7E-D0F3-4B35-A167-ACD19F5376C9.cxv
2008-01-17 23:44 2,048 —-a-w C:\WINDOWS\system32\drivers\F0161235-D5E8-4013-A5B5-A1D263A0043A.cxv
2008-01-17 22:36 5,120 —-a-w C:\WINDOWS\system32\drivers\6DD98783-C887-4DC9-8CEF-C7D431AE3495.cxv
2008-01-17 22:00 ——— d—–w C:\Program Files\Enigma Software Group
2008-01-17 20:26 ——— d—–w C:\Program Files\CyberLink
2008-01-17 20:21 ——— d—–w C:\Program Files\Starcraft
2008-01-17 18:32 ——— d—–w C:\Program Files\FableTLCMod
2008-01-17 17:43 1,700,352 —-a-w C:\WINDOWS\system32\gdiplus.dll
2008-01-16 19:22 6,094,848 —-a-w C:\WINDOWS\system32\Skyrocket.scr
2008-01-16 19:22 483,328 —-a-w C:\WINDOWS\system32\Helios.scr
2008-01-16 19:22 450,560 —-a-w C:\WINDOWS\system32\Euphoria.scr
2008-01-16 19:22 274,432 —-a-w C:\WINDOWS\system32\Cyclone.scr
2008-01-16 19:22 249,856 —-a-w C:\WINDOWS\system32\Flocks.scr
2008-01-16 19:22 245,760 —-a-w C:\WINDOWS\system32\Flux.scr
2008-01-16 19:22 237,568 —-a-w C:\WINDOWS\system32\SolarWinds.scr
2008-01-16 19:22 237,568 —-a-w C:\WINDOWS\system32\FieldLines.scr
2008-01-16 19:22 229,376 —-a-w C:\WINDOWS\system32\Plasma.scr
2008-01-16 19:22 1,908,736 —-a-w C:\WINDOWS\system32\Lattice.scr
2008-01-16 16:26 ——— d—–w C:\Program Files\MSXML 4.0
2008-01-15 23:35 ——— d—–w C:\Documents and Settings\Wilke\Application Data\Smith Micro
2008-01-15 23:20 ——— d—–w C:\Program Files\Verizon Wireless
2008-01-15 23:20 ——— d—–w C:\Program Files\PANTECH
2008-01-15 21:41 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-15 21:23 ——— d—–w C:\Program Files\Google
2008-01-15 21:06 ——— d—–w C:\Program Files\Common Files\Intuit
2008-01-15 21:06 ——— d—–w C:\Program Files\Common Files\AnswerWorks 4.0
2008-01-15 21:05 ——— d—–w C:\Program Files\Intuit
2008-01-15 21:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Intuit
2008-01-15 21:03 ——— d—–w C:\Program Files\Common Files\SWF Studio
2008-01-15 17:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Dell
2008-01-15 15:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\Support.com
2008-01-15 15:46 ——— d—–w C:\Program Files\Common Files\Motive
2008-01-15 15:46 ——— d—–w C:\Documents and Settings\All Users\Application Data\Motive
2008-01-14 22:01 ——— d—–w C:\Documents and Settings\Wilke\Application Data\CyberLink
2008-01-14 20:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-01-14 20:09 ——— d—–w C:\Documents and Settings\Wilke\Application Data\Template
2008-01-14 19:56 126,976 —-a-w C:\WINDOWS\War3Unin.exe
2008-01-14 19:56 ——— d—–w C:\Program Files\Warcraft III
2008-01-14 19:43 94,208 —-a-w C:\WINDOWS\ScUnin.exe
2008-01-14 18:50 ——— d—–w C:\Program Files\Microsoft Games
2008-01-14 17:58 ——— d—–w C:\Program Files\Common Files\Blizzard Entertainment
2008-01-14 17:08 ——— d—–w C:\Documents and Settings\Wilke\Application Data\Dell
2008-01-11 05:53 44,544 —-a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-10 23:34 ——— d—–w C:\Documents and Settings\Wilke\Application Data\Roxio
2008-01-10 23:34 ——— d—–w C:\Documents and Settings\LocalService\Application Data\Roxio
2008-01-10 23:34 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Roxio
2008-01-10 23:32 ——— d—–w C:\Program Files\Microsoft Works
2008-01-10 23:31 ——— d—–w C:\Program Files\MSECache
2008-01-10 23:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-10 23:29 ——— d—–w C:\Program Files\Dell Support Center
2008-01-10 23:29 ——— d—–w C:\Program Files\Dell
2008-01-10 23:29 ——— d—–w C:\Program Files\Common Files\supportsoft
2008-01-10 23:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-01-10 23:28 ——— d—–w C:\Program Files\Dell Network Assistant
2008-01-10 23:28 ——— d—–w C:\Program Files\Common Files\Adobe
2008-01-10 23:28 ——— d—–w C:\Documents and Settings\All Users\Application Data\SingleClick Systems
2008-01-10 23:26 ——— d—–w C:\Program Files\Roxio
2008-01-10 23:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Roxio
2008-01-10 23:25 ——— d—–w C:\Program Files\Common Files\Sonic Shared
2008-01-10 23:24 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-01-10 23:23 ——— d—–w C:\Program Files\Common Files\SureThing Shared
2008-01-10 23:23 ——— d—–w C:\Program Files\Common Files\Roxio Shared
2008-01-10 23:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sonic
2008-01-10 23:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-01-10 23:22 ——— d—–w C:\Program Files\Sigmatel
2008-01-10 23:20 ——— d—–w C:\Program Files\NetWaiting
2008-01-10 23:20 ——— d—–w C:\Program Files\Digital Line Detect
2008-01-10 23:20 ——— d—–w C:\Program Files\CONEXANT
2008-01-10 23:20 ——— d—–w C:\Documents and Settings\Wilke\Application Data\InstallShield
2008-01-10 23:20 ——— d—–w C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-01-10 23:19 ——— d—–w C:\Program Files\Modem Diagnostic Tool
2008-01-10 23:17 ——— d—–w C:\Program Files\Java
2008-01-10 23:17 ——— d—–w C:\Program Files\Common Files\Java
2008-01-10 23:15 ——— d—–w C:\Program Files\MSXML 6.0
2008-01-10 23:04 ——— d—–w C:\Program Files\Synaptics
2008-01-10 22:58 6,761 —-a-w C:\WINDOWS\system32\drivers\1028_Dell_VOS_1500.mrk
2007-12-19 23:01 347,136 —-a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 ——w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-14 16:32 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-08 05:21 3,592,192 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 11:01 625,664 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-12-06 11:00 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-06 04:59 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-02-29 14:23 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-06 16:34 8429568]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM63b544b5]
C:\WINDOWS\system32\vxkiisva.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
C:\WINDOWS\system32\WLTRAY.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-02-29 14:23 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\mljge.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2007-06-06 16:34 8429568 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVHotkey]
–a—— 2007-06-06 16:34 67584 C:\WINDOWS\system32\nvhotkey.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-06-06 16:34 81920 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2007-06-06 16:35 1626112 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
C:\Program Files\Dell\MediaDirect\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
–a—— 2007-06-06 16:28 405504 C:\WINDOWS\stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.12.6546-enUS-downloader.exe"=
"C:\\Program Files\\Intuit\\QuickBooks 2006\\QBDBMgrN.exe"=
"C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iWin Games\\iWinGames.exe"=
"C:\\Program Files\\iWin Games\\WebUpdater.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC

R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 11:35]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-10-09 19:56]
R3 DXEC02;DXEC02;C:\WINDOWS\system32\drivers\dxec02.sys [2006-11-02 13:31]
R3 PTDMBus;PANTECH USB Modem Composite Device Driver ;C:\WINDOWS\system32\DRIVERS\PTDMBus.sys [2007-08-17 20:56]
R3 PTDMMdm;PANTECH USB Modem Drivers ;C:\WINDOWS\system32\DRIVERS\PTDMMdm.sys [2007-08-17 20:56]
R3 PTDMVsp;PANTECH USB Modem Serial Port ;C:\WINDOWS\system32\DRIVERS\PTDMVsp.sys [2007-08-17 20:56]
S3 PTDMWWAN;PANTECH USB Modem WWAN Driver;C:\WINDOWS\system32\DRIVERS\PTDMWWAN.sys [2007-08-17 20:56]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 06:00]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-19 18:30:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-05 13:33:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-05 13:33:20
ComboFix-quarantined-files.txt 2008-03-05 18:33:18
ComboFix2.txt 2008-03-02 01:33:16
ComboFix3.txt 2008-03-01 21:27:23
.
2008-02-17 02:57:35 — E O F —




Sorry about not being able to get back to you over the weekend. thanks for all your help. the computer seems to be running better already!
Hello

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\mljge.exe
C:\WINDOWS\system32\vxkiisva.dll

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM63b544b5]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall



Also post a new HijackThis log
=( I was hoping it would be done! Heh, ya got my hopes up. Anyway, here is the new ComboFix:


ComboFix 08-03-01 - Wilke 2008-03-06 12:11:38.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1672 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Wilke\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-02-06 to 2008-03-06 )))))))))))))))))))))))))))))))
.

2008-02-28 16:42 . 2008-02-28 16:42 d——– C:\VundoFix Backups
2008-02-28 16:24 . 2008-02-28 16:52 d——– C:\Program Files\HJT
2008-02-28 13:54 . 2008-02-28 13:54 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-27 13:17 . 2008-03-01 16:22 21 –a—— C:\WINDOWS\pskt.ini
2008-02-27 10:36 . 2008-02-27 10:36 d——– C:\Documents and Settings\Wilke\Application Data\MSNInstaller
2008-02-27 10:04 . 2008-02-27 10:04 d——– C:\Documents and Settings\Wilke\Application Data\Apple Computer
2008-02-26 21:20 . 2008-03-01 16:22 99,434 –a—— C:\WINDOWS\BM63b544b5.xml
2008-02-21 16:39 . 2008-02-21 16:39 d——– C:\Documents and Settings\All Users\Application Data\iWin Games
2008-02-21 16:38 . 2008-02-21 16:38 d——– C:\Program Files\iWin.com Games
2008-02-21 16:38 . 2008-02-21 16:38 d——– C:\Program Files\iWin Games
2008-02-19 19:45 . 2008-02-19 19:45 334,848 –a—— C:\WINDOWS\system32\cuxnvprs.zwo
2008-02-19 13:30 . 2008-02-19 13:30 d——– C:\Program Files\Apple Software Update
2008-02-19 13:30 . 2008-02-27 10:59 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-19 13:30 . 2008-02-19 13:30 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-02-18 18:44 . 2008-02-18 18:38 691,545 –a—— C:\WINDOWS\unins000.exe
2008-02-18 18:44 . 2008-02-18 18:44 3,442 –a—— C:\WINDOWS\unins000.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-02 16:43 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-29 19:23 15,360 —-a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-02-29 19:23 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
2008-02-29 15:05 169,984 —-a-w C:\WINDOWS\system32\dllcache\msconfig.exe
2008-02-29 15:05 169,984 —-a-w C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe
2008-02-28 17:09 1,686 —-a-w C:\Documents and Settings\Wilke\Application Data\wklnhst.dat
2008-02-19 00:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-14 16:19 ——— d—–w C:\Documents and Settings\Wilke\Application Data\U3
2008-02-02 00:13 ——— d—–w C:\Program Files\World of Warcraft
2008-01-20 15:23 ——— d—–w C:\Program Files\CDKnet
2008-01-18 21:04 ——— d—–w C:\Program Files\Docking Station
2008-01-18 19:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-01-18 16:01 ——— d—–w C:\Program Files\Trend Micro
2008-01-18 03:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-18 03:08 ——— d—–w C:\Program Files\Lavasoft
2008-01-18 02:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-01-18 01:39 2,048 —-a-w C:\WINDOWS\system32\drivers\FABB7A7E-D0F3-4B35-A167-ACD19F5376C9.cxv
2008-01-17 23:44 2,048 —-a-w C:\WINDOWS\system32\drivers\F0161235-D5E8-4013-A5B5-A1D263A0043A.cxv
2008-01-17 22:36 5,120 —-a-w C:\WINDOWS\system32\drivers\6DD98783-C887-4DC9-8CEF-C7D431AE3495.cxv
2008-01-17 22:00 ——— d—–w C:\Program Files\Enigma Software Group
2008-01-17 20:26 ——— d—–w C:\Program Files\CyberLink
2008-01-17 20:21 ——— d—–w C:\Program Files\Starcraft
2008-01-17 18:32 ——— d—–w C:\Program Files\FableTLCMod
2008-01-17 17:43 1,700,352 —-a-w C:\WINDOWS\system32\gdiplus.dll
2008-01-16 19:22 6,094,848 —-a-w C:\WINDOWS\system32\Skyrocket.scr
2008-01-16 19:22 483,328 —-a-w C:\WINDOWS\system32\Helios.scr
2008-01-16 19:22 450,560 —-a-w C:\WINDOWS\system32\Euphoria.scr
2008-01-16 19:22 274,432 —-a-w C:\WINDOWS\system32\Cyclone.scr
2008-01-16 19:22 249,856 —-a-w C:\WINDOWS\system32\Flocks.scr
2008-01-16 19:22 245,760 —-a-w C:\WINDOWS\system32\Flux.scr
2008-01-16 19:22 237,568 —-a-w C:\WINDOWS\system32\SolarWinds.scr
2008-01-16 19:22 237,568 —-a-w C:\WINDOWS\system32\FieldLines.scr
2008-01-16 19:22 229,376 —-a-w C:\WINDOWS\system32\Plasma.scr
2008-01-16 19:22 1,908,736 —-a-w C:\WINDOWS\system32\Lattice.scr
2008-01-16 16:26 ——— d—–w C:\Program Files\MSXML 4.0
2008-01-15 23:35 ——— d—–w C:\Documents and Settings\Wilke\Application Data\Smith Micro
2008-01-15 23:20 ——— d—–w C:\Program Files\Verizon Wireless
2008-01-15 23:20 ——— d—–w C:\Program Files\PANTECH
2008-01-15 21:41 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-15 21:23 ——— d—–w C:\Program Files\Google
2008-01-15 21:06 ——— d—–w C:\Program Files\Common Files\Intuit
2008-01-15 21:06 ——— d—–w C:\Program Files\Common Files\AnswerWorks 4.0
2008-01-15 21:05 ——— d—–w C:\Program Files\Intuit
2008-01-15 21:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Intuit
2008-01-15 21:03 ——— d—–w C:\Program Files\Common Files\SWF Studio
2008-01-15 17:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Dell
2008-01-15 15:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\Support.com
2008-01-15 15:46 ——— d—–w C:\Program Files\Common Files\Motive
2008-01-15 15:46 ——— d—–w C:\Documents and Settings\All Users\Application Data\Motive
2008-01-14 22:01 ——— d—–w C:\Documents and Settings\Wilke\Application Data\CyberLink
2008-01-14 20:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-01-14 20:09 ——— d—–w C:\Documents and Settings\Wilke\Application Data\Template
2008-01-14 19:56 126,976 —-a-w C:\WINDOWS\War3Unin.exe
2008-01-14 19:56 ——— d—–w C:\Program Files\Warcraft III
2008-01-14 19:43 94,208 —-a-w C:\WINDOWS\ScUnin.exe
2008-01-14 18:50 ——— d—–w C:\Program Files\Microsoft Games
2008-01-14 17:58 ——— d—–w C:\Program Files\Common Files\Blizzard Entertainment
2008-01-14 17:08 ——— d—–w C:\Documents and Settings\Wilke\Application Data\Dell
2008-01-11 05:53 44,544 —-a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-10 23:34 ——— d—–w C:\Documents and Settings\Wilke\Application Data\Roxio
2008-01-10 23:34 ——— d—–w C:\Documents and Settings\LocalService\Application Data\Roxio
2008-01-10 23:34 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Roxio
2008-01-10 23:32 ——— d—–w C:\Program Files\Microsoft Works
2008-01-10 23:31 ——— d—–w C:\Program Files\MSECache
2008-01-10 23:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-10 23:29 ——— d—–w C:\Program Files\Dell Support Center
2008-01-10 23:29 ——— d—–w C:\Program Files\Dell
2008-01-10 23:29 ——— d—–w C:\Program Files\Common Files\supportsoft
2008-01-10 23:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-01-10 23:28 ——— d—–w C:\Program Files\Dell Network Assistant
2008-01-10 23:28 ——— d—–w C:\Program Files\Common Files\Adobe
2008-01-10 23:28 ——— d—–w C:\Documents and Settings\All Users\Application Data\SingleClick Systems
2008-01-10 23:26 ——— d—–w C:\Program Files\Roxio
2008-01-10 23:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Roxio
2008-01-10 23:25 ——— d—–w C:\Program Files\Common Files\Sonic Shared
2008-01-10 23:24 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-01-10 23:23 ——— d—–w C:\Program Files\Common Files\SureThing Shared
2008-01-10 23:23 ——— d—–w C:\Program Files\Common Files\Roxio Shared
2008-01-10 23:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sonic
2008-01-10 23:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-01-10 23:22 ——— d—–w C:\Program Files\Sigmatel
2008-01-10 23:20 ——— d—–w C:\Program Files\NetWaiting
2008-01-10 23:20 ——— d—–w C:\Program Files\Digital Line Detect
2008-01-10 23:20 ——— d—–w C:\Program Files\CONEXANT
2008-01-10 23:20 ——— d—–w C:\Documents and Settings\Wilke\Application Data\InstallShield
2008-01-10 23:20 ——— d—–w C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-01-10 23:19 ——— d—–w C:\Program Files\Modem Diagnostic Tool
2008-01-10 23:17 ——— d—–w C:\Program Files\Java
2008-01-10 23:17 ——— d—–w C:\Program Files\Common Files\Java
2008-01-10 23:15 ——— d—–w C:\Program Files\MSXML 6.0
2008-01-10 23:04 ——— d—–w C:\Program Files\Synaptics
2008-01-10 22:58 6,761 —-a-w C:\WINDOWS\system32\drivers\1028_Dell_VOS_1500.mrk
2007-12-19 23:01 347,136 —-a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 ——w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-14 16:32 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-08 05:21 3,592,192 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 11:01 625,664 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-12-06 11:00 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-06 04:59 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-02-29 14:23 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-06 16:34 8429568]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM63b544b5]
C:\WINDOWS\system32\vxkiisva.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
C:\WINDOWS\system32\WLTRAY.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-02-29 14:23 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\mljge.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2007-06-06 16:34 8429568 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVHotkey]
–a—— 2007-06-06 16:34 67584 C:\WINDOWS\system32\nvhotkey.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-06-06 16:34 81920 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2007-06-06 16:35 1626112 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
C:\Program Files\Dell\MediaDirect\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
–a—— 2007-06-06 16:28 405504 C:\WINDOWS\stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.12.6546-enUS-downloader.exe"=
"C:\\Program Files\\Intuit\\QuickBooks 2006\\QBDBMgrN.exe"=
"C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iWin Games\\iWinGames.exe"=
"C:\\Program Files\\iWin Games\\WebUpdater.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC

R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 11:35]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-10-09 19:56]
R3 DXEC02;DXEC02;C:\WINDOWS\system32\drivers\dxec02.sys [2006-11-02 13:31]
R3 PTDMBus;PANTECH USB Modem Composite Device Driver ;C:\WINDOWS\system32\DRIVERS\PTDMBus.sys [2007-08-17 20:56]
R3 PTDMMdm;PANTECH USB Modem Drivers ;C:\WINDOWS\system32\DRIVERS\PTDMMdm.sys [2007-08-17 20:56]
R3 PTDMVsp;PANTECH USB Modem Serial Port ;C:\WINDOWS\system32\DRIVERS\PTDMVsp.sys [2007-08-17 20:56]
S3 PTDMWWAN;PANTECH USB Modem WWAN Driver;C:\WINDOWS\system32\DRIVERS\PTDMWWAN.sys [2007-08-17 20:56]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 06:00]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-19 18:30:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-06 12:12:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-06 12:13:11
ComboFix-quarantined-files.txt 2008-03-06 17:13:09
ComboFix2.txt 2008-03-05 18:33:21
ComboFix3.txt 2008-03-02 01:33:16
ComboFix4.txt 2008-03-01 21:27:23
.
2008-02-17 02:57:35 — E O F —






And here is the new Hijackthis log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:18:22 PM, on 3/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=2080110
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/&s;=5nMMnMSypzYU763wFjyTdarNLP0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{653D37BF-2A4E-4A59-8723-B742E0CDB114}: NameServer = 69.78.96.14 66.174.95.44
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE (file missing)

–
End of file - 5083 bytes



If I ever meet whoever created this evil malware in a dark alley……… :angry:

Thanks again for the help.
Hello

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner and click Accept

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Here is the Kaspersky log: ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Friday, March 07, 2008 2:37:01 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 6/03/2008 Kaspersky Anti-Virus database records: 604356 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ E:\ Scan Statistics: Total number of scanned objects: 49155 Number of viruses found: 7 Number of infected objects: 45 Number of suspicious objects: 0 Duration of the scan process: 00:34:17 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\SingleClick Systems\HomeNet Manager\Logs\hnm_svc.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\SupportSoft\DellSupportCenter\SYSTEM\state\logs\sprtcmd.log Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Wilke\.housecall6.6\Quarantine\gebyy.exe.bac_a03456 Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\Wilke\.housecall6.6\Quarantine\pmnolji.dll.bac_a03456 Infected: Trojan-Downloader.Win32.Small.ibf skipped C:\Documents and Settings\Wilke\.housecall6.6\Quarantine\RCX2E.tmp.bac_a03456 Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\Wilke\.housecall6.6\Quarantine\RCX2F.tmp.bac_a03456 Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\Wilke\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ms03011.jar-62b6e396-47054c7a.zip/OwnClassLoader.class Infected: Exploit.Java.ByteVerify skipped C:\Documents and Settings\Wilke\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ms03011.jar-62b6e396-47054c7a.zip ZIP: infected - 1 skipped C:\Documents and Settings\Wilke\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Wilke\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Wilke\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Wilke\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Wilke\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Wilke\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Wilke\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Wilke\ntuser.dat.LOG Object is locked skipped C:\Program Files\iWin Games\iWinGamesHookIE.dll Infected: not-a-virus:AdWare.Win32.AdMedia.g skipped C:\Program Files\iWin.com Games\Mysteryville\iWinGamesSetupR.exe/data0008 Infected: not-a-virus:AdWare.Win32.AdMedia.g skipped C:\Program Files\iWin.com Games\Mysteryville\iWinGamesSetupR.exe NSIS: infected - 1 skipped C:\Program Files\Spybot - Search & Destroy\ACZDEY.scr Infected: Virus.Win32.Trats.d skipped C:\QooBox\Quarantine\C\WINDOWS\system32\agpodhkx.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\aiuwsevu.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\bmcmvehn.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\bmulqpbc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\btuqvsht.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\ctfmon.exe.tmp.vir Infected: Virus.Win32.Trats.d skipped C:\QooBox\Quarantine\C\WINDOWS\system32\etbdvbby.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\exotbqqr.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\fshdkshb.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\hfqduxws.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\hyrqvggu.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\jgyntljf.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\jpxgbhxb.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\lurpwqiv.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\mljge.exe.vir Infected: Virus.Win32.Trats.d skipped C:\QooBox\Quarantine\C\WINDOWS\system32\oxxnwkfc.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.bce skipped C:\QooBox\Quarantine\C\WINDOWS\system32\pynckqot.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\RCX11.tmp.vir Infected: Virus.Win32.Trats.d skipped C:\QooBox\Quarantine\C\WINDOWS\system32\RCX12.tmp.vir Infected: Virus.Win32.Trats.d skipped C:\QooBox\Quarantine\C\WINDOWS\system32\RCX13.tmp.vir Infected: Virus.Win32.Trats.d skipped C:\QooBox\Quarantine\C\WINDOWS\system32\RCXE.tmp.vir Infected: Virus.Win32.Trats.d skipped C:\QooBox\Quarantine\C\WINDOWS\system32\RCXF.tmp.vir Infected: Virus.Win32.Trats.d skipped C:\QooBox\Quarantine\C\WINDOWS\system32\tcwjvyss.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\ticekktj.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\ufetwqyt.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\vxkiisva.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\wacissqx.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\xbabwbkb.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\catchme2008-03-01_162556.50.zip/mljge.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dyx skipped C:\QooBox\Quarantine\catchme2008-03-01_162556.50.zip ZIP: infected - 1 skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000009.exe Infected: Virus.Win32.Trats.d skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000095.exe Infected: Virus.Win32.Trats.d skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000106.exe Infected: Virus.Win32.Trats.d skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000108.exe Infected: Virus.Win32.Trats.d skipped C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP5\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\ModemLog_PANTECH USB Modem #3.txt Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\DEFAULT Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SYSTEM Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\cuxnvprs.zwo Infected: not-a-virus:AdWare.Win32.Virtumonde.dyx skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed. thanks again.
Hello

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Program Files\iWin Games\iWinGamesHookIE.dll
C:\Program Files\iWin.com Games\Mysteryville\iWinGamesSetupR.exe
C:\Program Files\Spybot - Search & Destroy\ACZDEY.scr
C:\WINDOWS\system32\cuxnvprs.zwo


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall




Also tell me how your PC is running
I tried running ComboFix but it said that it was out of date, please download an updated version. Also, the iwin games thing, and mysteryville are a game my wife loaded from a CD that she bought. I wouldnt think (or would hope at least) that there wouldnt be malicious stuff on a CD she purchased. If so, lets get rid of it. But, she does play it (its like 'where's waldo' only your finding stuff in pictures). Running the combofix thing wont delete the program will it? The computer seems to be running alot better. i dont get redirects, but sometimes it does seem a tad 'sluggish'. The redirects were a problem, often sending me to inappropriate sites. But they havnt been popping up in a while. I have been gun shy to do much online though. but when i do it seems better. thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI