This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT Log File for another Virtumonde fix please!

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ran HJT and VundoFix. After Vundo was removed, my computer kept on trying to access some files I thought were killing me. One in particular, DDAYY.DLL is popping up quite frequently. Turning off my Spyware will allow this file to do its dirty work for some strange reason. Here's the HJT Log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:48:57 PM, on 3/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpHost.exe
C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\REGEDIT.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: (no name) - {22342B44-5B98-4B30-9D53-C182AD8DF217} - C:\WINDOWS\system32\vtusttr.dll
O2 - BHO: (no name) - {5DD6E636-6B74-4423-A195-0A6B0FF3B066} - C:\WINDOWS\system32\ddayy.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [BM53f89f9b] Rundll32.exe "C:\WINDOWS\system32\gxhyswwq.dll",s
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…html?p=ZRfox000
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O20 - Winlogon Notify: awtqnkh - awtqnkh.dll (file missing)
O20 - Winlogon Notify: vtusttr - C:\WINDOWS\SYSTEM32\vtusttr.dll
O23 - Service: McAfee Application Installer Cleanup (0226661205003209) (0226661205003209mcinstcleanup) - McAfee, Inc. - C:\WINDOWS\TEMP\022666~1.EXE
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 6383 bytes
Hi Sonic4EVA
Welcome to the What the tech Forums
My name is mschroe919 and I am going to read your log.
I would like to help you So if you would….
Please be patient and I will be back as soon as possible.
While I am off to reading your log please do these:

Thanks mschroe919
FIRST:
Lets show all file like this:
Windows XP

* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.
NEXT:
Please download ATF Cleaner by Atribune.

Download Here:
http://www.atribune.org/ccount/click.php?id=1

This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

Be back soon
Hi Sonic4EVA

NEXT

Download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
——————————————————————–
1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results"
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net
——————————————————————–
2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review


****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****


Good luck mschroe919
Hey, Ran both as ordered… here's the new combofix log…

ComboFix 08-03-08.2 - Jesterex 2008-03-08 22:57:08.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1476 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Programs\WinReanimator
C:\Documents and Settings\All Users\Start Menu\Programs\WinReanimator\Uninstall.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\WinReanimator\WinReanimator.lnk
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\ScreenSaver\Images\000B00D5.urr
C:\Program Files\FunWebProducts\Shared\Cache\AvatarSmallBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\FunBuddyIconBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MailStampBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\Messenger\liquxigin89104.dll
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\1.bin\F3BROVLY.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SHLLVW.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Cache\00053715.bin
C:\Program Files\MyWebSearch\bar\Cache\00053909.bin
C:\Program Files\MyWebSearch\bar\Cache\00053D9D.bin
C:\Program Files\MyWebSearch\bar\Cache\00054185.bin
C:\Program Files\MyWebSearch\bar\Cache\0009C47D
C:\Program Files\MyWebSearch\bar\Cache\0009CC3D
C:\Program Files\MyWebSearch\bar\Cache\0009CE60.bin
C:\Program Files\MyWebSearch\bar\Cache\0009D044.bin
C:\Program Files\MyWebSearch\bar\Cache\0009D10F.bin
C:\Program Files\MyWebSearch\bar\Cache\0009D1DA.bin
C:\Program Files\MyWebSearch\bar\Cache\005DFC6C
C:\Program Files\MyWebSearch\bar\Cache\0134A83C.bin
C:\Program Files\MyWebSearch\bar\Cache\0134A955.bin
C:\Program Files\MyWebSearch\bar\Cache\0134AABC.bin
C:\Program Files\MyWebSearch\bar\Cache\0134AC14.bin
C:\Program Files\MyWebSearch\bar\Cache\0523E10D
C:\Program Files\MyWebSearch\bar\Cache\0AFE02C7
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\icons\CM.ICO
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO
C:\Program Files\MyWebSearch\bar\icons\WB.ICO
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Message\COMMON\ask_logo.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\autoup.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\autoup.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\center.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\index.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\mid_dots.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\mws_logo.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\protect.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\shocked.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\stop.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\systray.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\systrayp.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\tp_grad.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\warn.gif
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
C:\Program Files\web buying
C:\Program Files\web buying\v1.8.8\wbuninst.exe
C:\Program Files\web buying\v1.8.8\webbuying.exe
C:\Program Files\WinReanimator
C:\Program Files\WinReanimator\data\daily.cvd
C:\Program Files\WinReanimator\htmlayout.dll
C:\Program Files\WinReanimator\install.exe
C:\Program Files\WinReanimator\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
C:\Program Files\WinReanimator\Microsoft.VC80.CRT\msvcm80.dll
C:\Program Files\WinReanimator\Microsoft.VC80.CRT\msvcp80.dll
C:\Program Files\WinReanimator\Microsoft.VC80.CRT\msvcr80.dll
C:\Program Files\WinReanimator\pthreadVC2.dll
C:\Program Files\WinReanimator\un.ico
C:\Program Files\WinReanimator\unzip32.dll
C:\Program Files\WinReanimator\WinReanimator.cfg
C:\Program Files\WinReanimator\WinReanimator.dll
C:\Program Files\WinReanimator\WinReanimator.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\sanR24
C:\Temp\sanR24\lDii.log
C:\temp\tn3
C:\WINDOWS\BM53f89f9b.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Fonts\'
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bgcyrkqs.dll
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\system32\c2
C:\WINDOWS\system32\c4
C:\WINDOWS\system32\c4\np89104.exe
C:\WINDOWS\system32\ddayy.dll
C:\WINDOWS\system32\drivers\ndisuioo.sys
C:\WINDOWS\system32\fmxebhqx.dll
C:\WINDOWS\system32\ftvmtasm.dll
C:\WINDOWS\system32\fviaarnj.dll
C:\WINDOWS\system32\gxhyswwq.dll
C:\WINDOWS\system32\iiicylti.dll
C:\WINDOWS\system32\k8
C:\WINDOWS\system32\k8\ravecom3.exe
C:\WINDOWS\system32\kmfpbom.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mljihec.dll
C:\WINDOWS\system32\oybaghcg.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\qasgkppp.dll
C:\WINDOWS\system32\rolcegcr.dll
C:\WINDOWS\system32\s7
C:\WINDOWS\system32\s7\gbsu011.exe
C:\WINDOWS\system32\sqkrycgb.ini
C:\WINDOWS\system32\ttrajelv.dll
C:\WINDOWS\system32\users32.dat
C:\WINDOWS\system32\vlejartt.ini
C:\WINDOWS\system32\vsbmovoh.dll
C:\WINDOWS\system32\vtusttr.dll
C:\WINDOWS\system32\winivstr.exe
C:\WINDOWS\system32\x3
C:\WINDOWS\system32\yyadd.ini
C:\WINDOWS\system32\yyadd.ini2

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\LEGACY_NDISUIOO
——-\ndisuioo


((((((((((((((((((((((((( Files Created from 2008-02-09 to 2008-03-09 )))))))))))))))))))))))))))))))
.

2008-03-08 22:50 . 2008-03-08 22:52 d——– C:\WINDOWS\LastGood
2008-03-08 22:50 . 2008-03-08 22:50 d——– C:\Program Files\Sigmatel
2008-03-08 22:50 . 2006-07-24 07:20 1,052,672 –a—— C:\WINDOWS\system32\stlang.dll
2008-03-08 22:50 . 2006-07-24 07:20 282,624 –a—— C:\WINDOWS\stsystra.exe
2008-03-08 06:55 . 2007-09-05 16:23 d——– C:\Documents and Settings\Administrator\Application Data\Roxio
2008-03-08 06:55 . 2007-09-05 16:17 d——– C:\Documents and Settings\Administrator\Application Data\GTek
2008-03-08 06:55 . 2007-09-05 16:22 d——– C:\Documents and Settings\Administrator\Application Data\Creative
2008-03-07 17:08 . 2008-03-07 17:08 d——– C:\Program Files\Trend Micro
2008-03-07 07:01 . 2008-03-07 07:01 d——– C:\Program Files\Lavasoft
2008-03-07 07:01 . 2008-03-07 07:03 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-07 06:52 . 2008-03-08 23:09 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-07 06:52 . 2007-12-10 14:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-07 06:52 . 2007-12-10 14:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-07 06:52 . 2008-02-01 12:55 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-07 06:52 . 2007-12-10 14:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-03-07 06:51 . 2008-03-07 06:55 d——– C:\Program Files\Spyware Doctor
2008-03-07 06:51 . 2008-03-07 06:51 d——– C:\Documents and Settings\Jesterex\Application Data\PC Tools
2008-03-07 06:39 . 2008-03-07 06:39 19,771 –a—— C:\WINDOWS\bubama.dl
2008-03-07 06:39 . 2008-03-07 06:39 19,609 –a—— C:\Documents and Settings\Jesterex\Application Data\bicikobitu.vbs
2008-03-07 06:39 . 2008-03-07 06:39 19,315 –a—— C:\Program Files\Common Files\otisexufy.reg
2008-03-07 06:39 . 2008-03-07 06:39 19,261 –a—— C:\WINDOWS\lyqe.sys
2008-03-07 06:39 . 2008-03-07 06:39 18,941 –a—— C:\Documents and Settings\All Users\Application Data\caduwad.exe
2008-03-07 06:39 . 2008-03-07 06:39 18,199 –a—— C:\WINDOWS\system32\lyrusicu.inf
2008-03-07 06:39 . 2008-03-07 06:39 17,504 –a—— C:\WINDOWS\system32\karupiqyce.pif
2008-03-07 06:39 . 2008-03-07 06:39 16,935 –a—— C:\Documents and Settings\All Users\Application Data\ehozemun.scr
2008-03-07 06:39 . 2008-03-07 06:39 16,138 –a—— C:\Documents and Settings\All Users\Application Data\ywabuvati.bin
2008-03-07 06:39 . 2008-03-07 06:39 15,776 –a—— C:\WINDOWS\ybyg.vbs
2008-03-07 06:39 . 2008-03-07 06:39 14,593 –a—— C:\WINDOWS\evyla.reg
2008-03-07 06:39 . 2008-03-07 06:39 13,629 –a—— C:\Documents and Settings\All Users\Application Data\igyxi.exe
2008-03-07 06:39 . 2008-03-07 06:39 13,256 –a—— C:\WINDOWS\ridolob.reg
2008-03-07 06:39 . 2008-03-07 06:39 12,264 –a—— C:\WINDOWS\vewiwuhy.dll
2008-03-07 06:39 . 2008-03-07 06:39 10,996 –a—— C:\WINDOWS\eleg._dl
2008-03-07 00:30 . 2008-03-07 00:30 58,368 –a—— C:\WINDOWS\system32\~.exe
2008-03-06 13:46 . 2008-03-06 13:46 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-06 13:34 . 2008-03-06 18:36 d——– C:\VundoFix Backups
2008-03-06 13:29 . 2008-03-06 13:29 167,545 –a—— C:\WINDOWS\system32\drivers\core.cache.dsk
2008-03-05 21:57 . 2008-03-05 21:57 d——– C:\Documents and Settings\Jesterex\Application Data\TrojanHunter
2008-03-05 21:55 . 2008-03-05 21:55 d——– C:\Program Files\TrojanHunter 4.6
2008-03-05 21:48 . 2008-03-05 21:48 d——– C:\Program Files\Security Task Manager
2008-03-05 21:48 . 2008-03-05 21:54 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-03-05 12:05 . 2008-03-06 06:53 1,307,623 –ahs—- C:\WINDOWS\system32\mpgtvqof.ini
2008-03-03 12:01 . 2008-03-04 12:01 1,303,138 –ahs—- C:\WINDOWS\system32\mmioguba.ini
2008-03-03 11:50 . 2008-03-03 11:50 d——– C:\Program Files\Common Files\Adobe
2008-03-02 19:00 . 2008-03-03 11:50 d——– C:\Program Files\Common Files\Adobe(2)
2008-03-02 16:42 . 2008-03-02 16:43 d——– C:\Program Files\TGTSoft
2008-03-02 16:39 . 2008-03-03 11:50 d——– C:\Program Files\iPod Music Converter
2008-03-02 16:18 . 2008-03-02 16:18 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2008-03-02 16:14 . 2008-03-07 00:34 d——– C:\WINDOWS\system32\iDlo18
2008-03-02 16:14 . 2008-03-08 23:00 d——– C:\Temp
2008-03-02 15:56 . 2008-03-02 15:56 d——– C:\Program Files\Free iPod Video Converter
2008-03-02 15:56 . 2004-05-25 17:06 417,792 –a—— C:\WINDOWS\system32\ac3filter.ax
2008-03-02 15:56 . 2005-02-27 21:48 356,352 –a—— C:\WINDOWS\system32\RealMediaSplitter.ax
2008-03-02 15:56 . 2004-01-10 17:02 258,048 –a—— C:\WINDOWS\system32\GplMpgDec.ax
2008-02-29 21:12 . 2005-11-13 22:40 89,360 –a—— C:\WINDOWS\system32\VB5DB.DLL
2008-02-29 21:11 . 2008-02-29 21:23 d——– C:\Unreal Anthology
2008-02-29 21:11 . 1997-07-19 17:01 118,781 –a—— C:\WINDOWS\system32\TABCTL32.ocx
2008-02-29 21:11 . 1998-01-24 03:39 110,725 –a—— C:\WINDOWS\system32\RICHTX32.ocx
2008-02-29 21:11 . 1995-07-26 01:00 98,588 –a—— C:\WINDOWS\system32\THREED32.ocx
2008-02-29 21:11 . 1995-07-26 01:00 48,640 –a—— C:\WINDOWS\system32\GRID32.ocx
2008-02-29 21:11 . 1997-01-16 10:11 44,831 –a—— C:\WINDOWS\system32\PICCLP32.ocx
2008-02-29 21:11 . 1995-07-26 01:00 43,502 –a—— C:\WINDOWS\system32\MSOUTL32.ocx
2008-02-29 18:14 . 2008-03-06 13:41 d——– C:\Program Files\Microsoft IntelliType Pro
2008-02-29 18:14 . 2008-02-29 18:14 d——– C:\Program Files\Microsoft IntelliPoint
2008-02-29 08:30 . 2008-02-29 08:30 d——– C:\WINDOWS\pix_office_wall
2008-02-29 08:30 . 2008-02-29 08:30 3,932,214 –a—— C:\WINDOWS\wall 1280.bmp
2008-02-29 08:27 . 2008-02-29 08:27 0 –a—— C:\WINDOWS\WB.ini
2008-02-27 20:30 . 2008-02-27 20:30 d–hsc— C:\Program Files\Common Files\WindowsLiveInstaller
2008-02-27 20:29 . 2008-02-27 20:30 d——– C:\Program Files\Windows Live
2008-02-27 20:29 . 2008-02-27 20:29 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-21 15:50 . 2008-02-21 15:50 d——– C:\Program Files\iTunes
2008-02-21 15:50 . 2008-02-21 15:50 d——– C:\Program Files\iPod
2008-02-21 15:50 . 2008-03-07 16:58 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-21 15:50 . 2008-02-21 15:50 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-21 07:04 . 2008-02-21 07:04 d——– C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-02-20 15:51 . 2008-02-20 15:51 d——– C:\Program Files\support.com
2008-02-20 15:51 . 2008-02-20 15:51 d——– C:\Documents and Settings\All Users\Application Data\Support.com
2008-02-20 15:51 . 2008-02-20 15:51 1,090 –a—— C:\net_save.dna
2008-02-19 19:42 . 2008-02-19 19:51 d——– C:\Netgear
2008-02-16 22:48 . 2008-02-16 22:48 d——– C:\WINDOWS\Wireless
2008-02-12 19:03 . 2008-02-12 19:05 50 –a—— C:\tmp.bat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-09 06:52 ——— d—–w C:\Program Files\McAfee
2008-03-08 01:03 ——— d—–w C:\Documents and Settings\Jesterex\Application Data\LimeWire
2008-03-08 00:59 ——— d—–w C:\Documents and Settings\Jesterex\Application Data\Hamachi
2008-03-07 15:01 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-04 15:29 ——— d—–w C:\Program Files\YVD
2008-03-03 00:24 ——— d—–w C:\Program Files\Java
2008-03-01 05:11 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-29 16:04 1,174 —-a-w C:\Documents and Settings\Jesterex\Application Data\wklnhst.dat
2008-02-28 04:31 ——— d—–w C:\Program Files\MSN Messenger
2008-02-21 15:05 ——— d—–w C:\Program Files\AIM6
2008-02-21 15:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-21 15:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-17 22:01 ——— d—–w C:\Program Files\Pcsx2_0.9.4
2008-02-09 20:56 ——— d—–w C:\Program Files\QuickTime
2008-02-06 17:51 171,400 —-a-w C:\WINDOWS\system32\drivers\mfehidk.sys
2008-02-03 03:14 ——— d—–w C:\Program Files\World of Warcraft
2008-01-26 05:36 ——— d—–w C:\Documents and Settings\Jesterex\Application Data\InstallShield Installation Information
2008-01-26 05:22 ——— d—–w C:\Program Files\Unreal Tournament 3
2008-01-26 05:22 ——— d—–w C:\Program Files\AGEIA Technologies
2008-01-24 01:28 ——— d—–w C:\Program Files\2nd Story Software
2008-01-15 05:48 ——— d—–w C:\Program Files\DivX
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-05-27 11:21 8429568]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 07:20 282624 C:\WINDOWS\stsystra.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonuiX.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtqnkh]
awtqnkh.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtusttr]
vtusttr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll 2007-03-05 17:36 140976 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R0 DigiFilter;DigiFilter;C:\WINDOWS\system32\drivers\DigiFilt.sys [2006-11-13 20:38]
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 07:35]
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2007-05-17 13:45]
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2006-02-14 20:40]
S2 0298751205045554mcinstcleanup;McAfee Application Installer Cleanup (0298751205045554);C:\WINDOWS\TEMP\029875~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S3 iLokDrvr;iLok;C:\WINDOWS\system32\DRIVERS\iLokDrvr.sys [2006-10-05 16:06]
S4 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 13:38]

*Newly Created Service* - 0298751205045554MCINSTCLEANUP
.
Contents of the 'Scheduled Tasks' folder
"2008-03-06 23:45:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-09 06:55:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-15 09:00:01 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-03-01 09:00:01 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2007-10-30 16:18:12 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_LifeExp_exe.job"
- C:\Program Files\Microsoft LifeCam\LifeExp.exe
"2007-10-30 15:55:57 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_setup_exe.job"
- E:\setup.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-08 23:09:34
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\ArcSoft\PhotoImpression 5\share\pihook.dll
-> C:\WINDOWS\system32\DLAAPI_W.DLL
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
.
**************************************************************************
.
Completion time: 2008-03-08 23:12:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-09 07:12:32
.
2008-02-13 00:08:04 — E O F —

and here's HiJackThis.exe

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:15:54 PM, on 3/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Windows Live Toolbar\msn_sl.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…html?p=ZRfox000
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O20 - Winlogon Notify: awtqnkh - awtqnkh.dll (file missing)
O20 - Winlogon Notify: vtusttr - vtusttr.dll (file missing)
O23 - Service: McAfee Application Installer Cleanup (0298751205045554) (0298751205045554mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\029875~1.EXE (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 6204 bytes

At the current moment, my computer seems to have made it through. Minimal damage done, but still a bit sluggish. Also, reran spyware doctor after everything was completed. There are still the other few viruses with low/medium risks. These include Trojan.Generic, Trojan.Fakealert, and Adaware.Rabio not to mention RogueAntiSpyware.SpywareNo. Currently, none of these are active.
Hi Sonic4EVAl.
Sorry about getting back late. Your log was a little complex.
As well as I got tied up with th Grandkids (who are my life)
Your doing well here.
NOTE before we continue we need to make sure
all you real time programs are sdisable, as they\ma effect the fix.

Such as Spyware Doctor
Here is how:
SpywareDoctor

Spyware Doctor's OnGuard protective functionality may interfere with certain HijackThis fixes we need to make. Please follow these instructions to disable it:

To deactivate Spyware Doctor's OnGuard Tools

1. From within Spyware Doctor, click the "OnGuard" button on the left side.
2. Uncheck "Activate OnGuard"
You can reenable it once your system is clean

NEXT:

MCAFEE ANTIVIRUS
Please navigate to the system tray on the bottom right hand corner and look for a [external image: Posted Image] sign.
  • right-click it -> chose "Exit."
  • a popup will warn that protection will now be disabled. Click on "Yes" to disable the Antivirus guard.
You succesfully disabled the McAfee Guard.
.You can reenable it once your system is clean.
NEXT:
1. Please open Notepad
Click Start , then Run
Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:


KillAll::

File::
C:\WINDOWS\bubama.dl
C:\Documents and Settings\Jesterex\Application Data\bicikobitu.vbs
C:\Program Files\Common Files\otisexufy.reg
C:\WINDOWS\lyqe.sys
C:\Documents and Settings\All Users\Application Data\caduwad.exe
C:\WINDOWS\system32\lyrusicu.inf
C:\WINDOWS\system32\karupiqyce.pif
C:\Documents and Settings\All Users\Application Data\ehozemun.scr
C:\Documents and Settings\All Users\Application Data\ywabuvati.bin
C:\WINDOWS\ybyg.vbs
C:\WINDOWS\evyla.reg
C:\Documents and Settings\All Users\Application Data\igyxi.exe
C:\WINDOWS\ridolob.reg
C:\WINDOWS\vewiwuhy.dll
C:\WINDOWS\eleg._dl
C:\WINDOWS\system32\~.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\mpgtvqof.ini
C:\WINDOWS\system32\mmioguba.ini
C:\WINDOWS\system32\vbzip10.dll
C:\tmp.bat
C:\net_save.dna
C:\WINDOWS\wall 1280.bmp

Folder:
C:\WINDOWS\system32\iDlo18

Driver::
0298751205045554mcinstcleanup

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtqnkh]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtusttr][/b]
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.
[external image: Posted Image]
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Next, re-enable all the programs that you disabled prior to running ComboFix.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

NEXT:
Reboot and when rebooted:
Using Internet Explorer, please do a Kaspersky online scan] This scan takes about 60 minutes to complete.

Answer Yes, when prompted to install an ActiveX component.
The program will then begin downloading the latest definition files.
Once the files have been downloaded click on NEXT
Locate the Scan Settings button & configure as follows:
Scan using the following Anti-Virus database:
Extended
Scan Options:
Scan Archives
Scan Mail Bases
Click OK & have it scan My Computer
* Turn off the real time scanner of any existing antivirus program while performing the online scan
Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

[external image: Posted Image]

Click the Save as Text button to save the file to your desktop and post it in your next reply along with a fresh HijackThis log
along with ComboFix.txt
when you post let me know how your pc is behaving
Good Luck mschroe919
ComboFix 08-03-08.2 - Jesterex 2008-03-09 19:53:21.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1682 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jesterex\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Documents and Settings\All Users\Application Data\caduwad.exe
C:\Documents and Settings\All Users\Application Data\ehozemun.scr
C:\Documents and Settings\All Users\Application Data\igyxi.exe
C:\Documents and Settings\All Users\Application Data\ywabuvati.bin
C:\Documents and Settings\Jesterex\Application Data\bicikobitu.vbs
C:\net_save.dna
C:\Program Files\Common Files\otisexufy.reg
C:\tmp.bat
C:\WINDOWS\bubama.dl
C:\WINDOWS\eleg._dl
C:\WINDOWS\evyla.reg
C:\WINDOWS\lyqe.sys
C:\WINDOWS\ridolob.reg
C:\WINDOWS\system32\~.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\karupiqyce.pif
C:\WINDOWS\system32\lyrusicu.inf
C:\WINDOWS\system32\mmioguba.ini
C:\WINDOWS\system32\mpgtvqof.ini
C:\WINDOWS\system32\vbzip10.dll
C:\WINDOWS\vewiwuhy.dll
C:\WINDOWS\wall 1280.bmp
C:\WINDOWS\ybyg.vbs
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\caduwad.exe
C:\Documents and Settings\All Users\Application Data\ehozemun.scr
C:\Documents and Settings\All Users\Application Data\igyxi.exe
C:\Documents and Settings\All Users\Application Data\ywabuvati.bin
C:\Documents and Settings\Jesterex\Application Data\bicikobitu.vbs
C:\net_save.dna
C:\Program Files\Common Files\otisexufy.reg
C:\tmp.bat
C:\WINDOWS\bubama.dl
C:\WINDOWS\eleg._dl
C:\WINDOWS\evyla.reg
C:\WINDOWS\lyqe.sys
C:\WINDOWS\ridolob.reg
C:\WINDOWS\system32\~.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\karupiqyce.pif
C:\WINDOWS\system32\lyrusicu.inf
C:\WINDOWS\system32\mmioguba.ini
C:\WINDOWS\system32\mpgtvqof.ini
C:\WINDOWS\system32\vbzip10.dll
C:\WINDOWS\vewiwuhy.dll
C:\WINDOWS\wall 1280.bmp
C:\WINDOWS\ybyg.vbs

.
((((((((((((((((((((((((( Files Created from 2008-02-10 to 2008-03-10 )))))))))))))))))))))))))))))))
.

2008-03-09 04:31 . 2008-03-09 04:31 d——– C:\WINDOWS\LastGood.Tmp
2008-03-09 00:27 . 2008-03-09 00:27 2,560 –a—— C:\WINDOWS\_MSRSTRT.EXE
2008-03-08 23:50 . 2008-03-08 23:50 d——– C:\Program Files\Sigmatel
2008-03-08 23:50 . 2006-07-24 08:20 1,052,672 –a—— C:\WINDOWS\system32\stlang.dll
2008-03-08 23:50 . 2006-07-24 08:20 282,624 –a—— C:\WINDOWS\stsystra.exe
2008-03-08 07:55 . 2007-09-05 17:23 d——– C:\Documents and Settings\Administrator\Application Data\Roxio
2008-03-08 07:55 . 2007-09-05 17:17 d——– C:\Documents and Settings\Administrator\Application Data\GTek
2008-03-08 07:55 . 2007-09-05 17:22 d——– C:\Documents and Settings\Administrator\Application Data\Creative
2008-03-07 18:08 . 2008-03-07 18:08 d——– C:\Program Files\Trend Micro
2008-03-07 08:01 . 2008-03-07 08:01 d——– C:\Program Files\Lavasoft
2008-03-07 08:01 . 2008-03-07 08:03 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-07 07:52 . 2008-03-09 19:52 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-07 07:52 . 2007-12-10 15:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-07 07:52 . 2007-12-10 15:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-07 07:52 . 2008-02-01 13:55 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-07 07:52 . 2007-12-10 15:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-03-07 07:51 . 2008-03-07 07:55 d——– C:\Program Files\Spyware Doctor
2008-03-07 07:51 . 2008-03-07 07:51 d——– C:\Documents and Settings\Jesterex\Application Data\PC Tools
2008-03-06 14:46 . 2008-03-06 14:46 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-06 14:34 . 2008-03-06 19:36 d——– C:\VundoFix Backups
2008-03-05 22:57 . 2008-03-05 22:57 d——– C:\Documents and Settings\Jesterex\Application Data\TrojanHunter
2008-03-05 22:55 . 2008-03-09 00:26 d——– C:\Program Files\TrojanHunter 4.6
2008-03-05 22:48 . 2008-03-05 22:48 d——– C:\Program Files\Security Task Manager
2008-03-05 22:48 . 2008-03-05 22:54 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-03-03 12:50 . 2008-03-03 12:50 d——– C:\Program Files\Common Files\Adobe
2008-03-02 20:00 . 2008-03-03 12:50 d——– C:\Program Files\Common Files\Adobe(2)
2008-03-02 17:42 . 2008-03-02 17:43 d——– C:\Program Files\TGTSoft
2008-03-02 17:39 . 2008-03-03 12:50 d——– C:\Program Files\iPod Music Converter
2008-03-02 17:14 . 2008-03-07 01:34 d——– C:\WINDOWS\system32\iDlo18
2008-03-02 17:14 . 2008-03-09 00:00 d——– C:\Temp
2008-03-02 16:56 . 2008-03-02 16:56 d——– C:\Program Files\Free iPod Video Converter
2008-03-02 16:56 . 2004-05-25 18:06 417,792 –a—— C:\WINDOWS\system32\ac3filter.ax
2008-03-02 16:56 . 2005-02-27 22:48 356,352 –a—— C:\WINDOWS\system32\RealMediaSplitter.ax
2008-03-02 16:56 . 2004-01-10 18:02 258,048 –a—— C:\WINDOWS\system32\GplMpgDec.ax
2008-02-29 22:12 . 2005-11-13 23:40 89,360 –a—— C:\WINDOWS\system32\VB5DB.DLL
2008-02-29 22:11 . 2008-02-29 22:23 d——– C:\Unreal Anthology
2008-02-29 22:11 . 1997-07-19 18:01 118,781 –a—— C:\WINDOWS\system32\TABCTL32.ocx
2008-02-29 22:11 . 1998-01-24 04:39 110,725 –a—— C:\WINDOWS\system32\RICHTX32.ocx
2008-02-29 22:11 . 1995-07-26 02:00 98,588 –a—— C:\WINDOWS\system32\THREED32.ocx
2008-02-29 22:11 . 1995-07-26 02:00 48,640 –a—— C:\WINDOWS\system32\GRID32.ocx
2008-02-29 22:11 . 1997-01-16 11:11 44,831 –a—— C:\WINDOWS\system32\PICCLP32.ocx
2008-02-29 22:11 . 1995-07-26 02:00 43,502 –a—— C:\WINDOWS\system32\MSOUTL32.ocx
2008-02-29 19:14 . 2008-03-06 14:41 d——– C:\Program Files\Microsoft IntelliType Pro
2008-02-29 19:14 . 2008-02-29 19:14 d——– C:\Program Files\Microsoft IntelliPoint
2008-02-29 09:30 . 2008-02-29 09:30 d——– C:\WINDOWS\pix_office_wall
2008-02-29 09:27 . 2008-02-29 09:27 0 ——— C:\WINDOWS\WB.ini
2008-02-27 21:30 . 2008-02-27 21:30 d–hsc— C:\Program Files\Common Files\WindowsLiveInstaller
2008-02-27 21:29 . 2008-02-27 21:30 d——– C:\Program Files\Windows Live
2008-02-27 21:29 . 2008-02-27 21:29 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-21 16:50 . 2008-02-21 16:50 d——– C:\Program Files\iTunes
2008-02-21 16:50 . 2008-02-21 16:50 d——– C:\Program Files\iPod
2008-02-21 16:50 . 2008-03-07 17:58 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-21 16:50 . 2008-02-21 16:50 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-21 08:04 . 2008-02-21 08:04 d——– C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-02-20 16:51 . 2008-02-20 16:51 d——– C:\Program Files\support.com
2008-02-20 16:51 . 2008-02-20 16:51 d——– C:\Documents and Settings\All Users\Application Data\Support.com
2008-02-19 20:42 . 2008-02-19 20:51 d——– C:\Netgear
2008-02-16 23:48 . 2008-02-16 23:48 d——– C:\WINDOWS\Wireless

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-09 22:52 1,174 —-a-w C:\Documents and Settings\Jesterex\Application Data\wklnhst.dat
2008-03-09 07:28 ——— d—–w C:\Program Files\Google
2008-03-09 07:26 ——— d—–w C:\Program Files\Common Files\Stardock
2008-03-09 06:52 ——— d—–w C:\Program Files\McAfee
2008-03-08 01:03 ——— d—–w C:\Documents and Settings\Jesterex\Application Data\LimeWire
2008-03-08 00:59 ——— d—–w C:\Documents and Settings\Jesterex\Application Data\Hamachi
2008-03-07 15:01 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-05 14:54 430,080 ——w C:\WINDOWS\Fonts\Setup.exe
2008-03-04 23:21 316,928 —-a-w C:\WINDOWS\Fonts\rar.exe
2008-03-04 15:29 ——— d—–w C:\Program Files\YVD
2008-03-03 00:24 ——— d—–w C:\Program Files\Java
2008-03-01 05:11 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-28 04:31 ——— d—–w C:\Program Files\MSN Messenger
2008-02-21 15:05 ——— d—–w C:\Program Files\AIM6
2008-02-21 15:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-21 15:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-17 22:01 ——— d—–w C:\Program Files\Pcsx2_0.9.4
2008-02-09 20:56 ——— d—–w C:\Program Files\QuickTime
2008-02-06 17:51 171,400 —-a-w C:\WINDOWS\system32\drivers\mfehidk.sys
2008-02-03 03:14 ——— d—–w C:\Program Files\World of Warcraft
2008-01-26 05:36 ——— d—–w C:\Documents and Settings\Jesterex\Application Data\InstallShield Installation Information
2008-01-26 05:22 ——— d—–w C:\Program Files\Unreal Tournament 3
2008-01-26 05:22 ——— d—–w C:\Program Files\AGEIA Technologies
2008-01-24 01:28 ——— d—–w C:\Program Files\2nd Story Software
2008-01-15 05:48 ——— d—–w C:\Program Files\DivX
.

((((((((((((((((((((((((((((( snapshot@2008-03-08_23.12.15.15 )))))))))))))))))))))))))))))))))))))))))
.
- 2000-08-31 16:00:00 163,328 —-a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2000-08-31 15:00:00 163,328 —-a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
- 2000-08-31 16:00:00 28,160 —-a-w C:\WINDOWS\Nircmd.exe
+ 2000-08-31 15:00:00 28,160 —-a-w C:\WINDOWS\Nircmd.exe
- 2000-08-31 16:00:00 161,792 —-a-w C:\WINDOWS\system32\swreg.exe
+ 2000-08-31 15:00:00 161,792 —-a-w C:\WINDOWS\system32\swreg.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 09:15 50528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-05-27 12:21 8429568]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 08:20 282624 C:\WINDOWS\stsystra.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonui.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtusttr]
vtusttr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R0 DigiFilter;DigiFilter;C:\WINDOWS\system32\drivers\DigiFilt.sys [2006-11-13 21:38]
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 08:35]
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2007-05-17 14:45]
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2006-02-14 21:40]
S2 0189591205062280mcinstcleanup;McAfee Application Installer Cleanup (0189591205062280);C:\WINDOWS\TEMP\018959~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S3 iLokDrvr;iLok;C:\WINDOWS\system32\DRIVERS\iLokDrvr.sys [2006-10-05 17:06]
S4 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38]

*Newly Created Service* - 0189591205062280MCINSTCLEANUP
.
Contents of the 'Scheduled Tasks' folder
"2008-03-06 23:45:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-10 02:55:03 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-15 09:00:01 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-03-01 09:00:01 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2007-10-30 16:18:12 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_LifeExp_exe.job"
- C:\Program Files\Microsoft LifeCam\LifeExp.exe
"2007-10-30 15:55:57 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_setup_exe.job"
- E:\setup.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-09 19:58:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\ArcSoft\PhotoImpression 5\share\pihook.dll
-> C:\WINDOWS\system32\DLAAPI_W.DLL
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-03-09 20:02:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-10 03:02:52
ComboFix2.txt 2008-03-09 07:12:37
.
2008-02-13 00:08:04 — E O F —

Here's the new combofix log after your instructions. I couldn't completely exit McAfee, but it didn't interfere too much. Also, AIM, Yahoo, and MSN were booted up during ComboFix… it's normal for the computer to do that, but I'm not sure if it was normal while combofix was running. I'm currently going through Kaspersky… so I'll get back to you on that. Would you like another HJT log after Kaspersky?
I can't seem to get the Kaspersky report onto this forum. However, it's got 20 viruses and more than 20000 infections, and i did save the website. Here's the current HJT log after all that.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:27:37 PM, on 3/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\ctfmon.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…html?p=ZRfox000
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: vtusttr - vtusttr.dll (file missing)
O23 - Service: McAfee Application Installer Cleanup (0189591205062280) (0189591205062280mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\018959~1.EXE (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 6186 bytes
Hi Sonic4EVAl.,
Way to sorry about being so late. Had a family problem took me away.

I can't seem to get the Kaspersky report onto this forum. However, it's got 20 viruses and more than 20000 infections, and i did save the website.

According to your log thats not so, but I am taking steps to check it out.
did you disable all real time
Spyware Doctor
TrojanHunter
MCAFEE ANTIVIRUS
NEXT:
NOTE before we continue we need to make sure
all you real time programs are sdisable, as they\ma effect the fix.

Such as Spyware Doctor
Here is how:
SpywareDoctor

Spyware Doctor's OnGuard protective functionality may interfere with certain HijackThis fixes we need to make. Please follow these instructions to disable it:

To deactivate Spyware Doctor's OnGuard Tools

1. From within Spyware Doctor, click the "OnGuard" button on the left side.
2. Uncheck "Activate OnGuard"
You can reenable it once your system is clean

NEXT:

MCAFEE ANTIVIRUS
Please navigate to the system tray on the bottom right hand corner and look for a [external image: Posted Image] sign.
  • right-click it -> chose "Exit."
  • a popup will warn that protection will now be disabled. Click on "Yes" to disable the Antivirus guard.
You succesfully disabled the McAfee Guard.
.You can reenable it once your system is clean.
NEXT:
1. Please open Notepad
Click Start , then Run
Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:
KillAll::

C:\WINDOWS\pix_office_wall
C:\Documents and Settings\Jesterex\Application Data\wklnhst.dat

Folder:
C:\WINDOWS\system32\iDlo18

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtusttr]
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.
[external image: Posted Image]
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Next, re-enable all the programs that you disabled prior to running ComboFix.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
NEXT:
Reboot and when rebooted:
re-enable your spyware doctor
Now try your Spyware Doctor scan.
1. Click the "Settings" button on the left side of the Spyware Doctor window.

2. Underneath "Pick a category", choose "Log Settings".

3. Underneath the checkboxes you should see several log file entries noted by the date/time of the entry.
Post a new HJT log and report on scan results as well, along with ComboFix.txt please.
good luck mschroe919
The only program I am not able to disable is McAfee… all others have been disabled. I'm about to run ComboFix again with the new script. I'll reply when that's done.
NEW COMBOFIX

ComboFix 08-03-08.2 - Jesterex 2008-03-12 6:25:22.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1606 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jesterex\Desktop\CFScript.txt.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-02-12 to 2008-03-12 )))))))))))))))))))))))))))))))
.

2008-03-10 14:01 . 2008-03-10 14:01 d——– C:\Program Files\LimeWire
2008-03-10 13:59 . 2008-03-10 13:59 d——– C:\Program Files\DNA
2008-03-10 13:59 . 2008-03-10 13:59 d——– C:\Program Files\BitTorrent
2008-03-10 13:59 . 2008-03-12 06:18 d——– C:\Documents and Settings\Jesterex\Application Data\DNA
2008-03-10 13:59 . 2008-03-10 18:47 d——– C:\Documents and Settings\Jesterex\Application Data\BitTorrent
2008-03-10 11:39 . 2008-03-12 04:29 d——– C:\WINDOWS\LastGood.Tmp
2008-03-09 20:05 . 2008-03-09 20:05 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-03-09 20:05 . 2008-03-09 20:05 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-09 00:27 . 2008-03-09 00:27 2,560 –a—— C:\WINDOWS\_MSRSTRT.EXE
2008-03-08 23:50 . 2008-03-08 23:50 d——– C:\Program Files\Sigmatel
2008-03-08 23:50 . 2006-07-24 08:20 1,052,672 –a—— C:\WINDOWS\system32\stlang.dll
2008-03-08 23:50 . 2006-07-24 08:20 282,624 –a—— C:\WINDOWS\stsystra.exe
2008-03-08 07:55 . 2007-09-05 17:23 d——– C:\Documents and Settings\Administrator\Application Data\Roxio
2008-03-08 07:55 . 2007-09-05 17:17 d——– C:\Documents and Settings\Administrator\Application Data\GTek
2008-03-08 07:55 . 2007-09-05 17:22 d——– C:\Documents and Settings\Administrator\Application Data\Creative
2008-03-07 18:08 . 2008-03-07 18:08 d——– C:\Program Files\Trend Micro
2008-03-07 08:01 . 2008-03-07 08:01 d——– C:\Program Files\Lavasoft
2008-03-07 08:01 . 2008-03-07 08:03 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-07 07:52 . 2008-03-09 19:52 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-07 07:52 . 2007-12-10 15:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-07 07:52 . 2007-12-10 15:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-07 07:52 . 2008-02-01 13:55 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-07 07:52 . 2007-12-10 15:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-03-07 07:51 . 2008-03-07 07:55 d——– C:\Program Files\Spyware Doctor
2008-03-07 07:51 . 2008-03-07 07:51 d——– C:\Documents and Settings\Jesterex\Application Data\PC Tools
2008-03-06 14:46 . 2008-03-06 14:46 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-06 14:34 . 2008-03-06 19:36 d——– C:\VundoFix Backups
2008-03-05 22:57 . 2008-03-05 22:57 d——– C:\Documents and Settings\Jesterex\Application Data\TrojanHunter
2008-03-05 22:55 . 2008-03-09 00:26 d——– C:\Program Files\TrojanHunter 4.6
2008-03-05 22:48 . 2008-03-05 22:48 d——– C:\Program Files\Security Task Manager
2008-03-05 22:48 . 2008-03-05 22:54 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-03-03 12:50 . 2008-03-03 12:50 d——– C:\Program Files\Common Files\Adobe
2008-03-02 20:00 . 2008-03-03 12:50 d——– C:\Program Files\Common Files\Adobe(2)
2008-03-02 17:42 . 2008-03-02 17:43 d——– C:\Program Files\TGTSoft
2008-03-02 17:39 . 2008-03-03 12:50 d——– C:\Program Files\iPod Music Converter
2008-03-02 17:14 . 2008-03-07 01:34 d——– C:\WINDOWS\system32\iDlo18
2008-03-02 17:14 . 2008-03-09 00:00 d——– C:\Temp
2008-03-02 16:56 . 2008-03-02 16:56 d——– C:\Program Files\Free iPod Video Converter
2008-03-02 16:56 . 2004-05-25 18:06 417,792 –a—— C:\WINDOWS\system32\ac3filter.ax
2008-03-02 16:56 . 2005-02-27 22:48 356,352 –a—— C:\WINDOWS\system32\RealMediaSplitter.ax
2008-03-02 16:56 . 2004-01-10 18:02 258,048 –a—— C:\WINDOWS\system32\GplMpgDec.ax
2008-02-29 22:12 . 2005-11-13 23:40 89,360 –a—— C:\WINDOWS\system32\VB5DB.DLL
2008-02-29 22:11 . 2008-02-29 22:23 d——– C:\Unreal Anthology
2008-02-29 22:11 . 1997-07-19 18:01 118,781 –a—— C:\WINDOWS\system32\TABCTL32.ocx
2008-02-29 22:11 . 1998-01-24 04:39 110,725 –a—— C:\WINDOWS\system32\RICHTX32.ocx
2008-02-29 22:11 . 1995-07-26 02:00 98,588 –a—— C:\WINDOWS\system32\THREED32.ocx
2008-02-29 22:11 . 1995-07-26 02:00 48,640 –a—— C:\WINDOWS\system32\GRID32.ocx
2008-02-29 22:11 . 1997-01-16 11:11 44,831 –a—— C:\WINDOWS\system32\PICCLP32.ocx
2008-02-29 22:11 . 1995-07-26 02:00 43,502 –a—— C:\WINDOWS\system32\MSOUTL32.ocx
2008-02-29 19:14 . 2008-03-06 14:41 d——– C:\Program Files\Microsoft IntelliType Pro
2008-02-29 19:14 . 2008-02-29 19:14 d——– C:\Program Files\Microsoft IntelliPoint
2008-02-29 09:30 . 2008-02-29 09:30 d——– C:\WINDOWS\pix_office_wall
2008-02-29 09:27 . 2008-02-29 09:27 0 ——— C:\WINDOWS\WB.ini
2008-02-27 21:30 . 2008-02-27 21:30 d–hsc— C:\Program Files\Common Files\WindowsLiveInstaller
2008-02-27 21:29 . 2008-02-27 21:30 d——– C:\Program Files\Windows Live
2008-02-27 21:29 . 2008-02-27 21:29 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-21 16:50 . 2008-02-21 16:50 d——– C:\Program Files\iTunes
2008-02-21 16:50 . 2008-02-21 16:50 d——– C:\Program Files\iPod
2008-02-21 08:04 . 2008-02-21 08:04 d——– C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-02-20 16:51 . 2008-02-20 16:51 d——– C:\Program Files\support.com
2008-02-20 16:51 . 2008-02-20 16:51 d——– C:\Documents and Settings\All Users\Application Data\Support.com
2008-02-19 20:42 . 2008-02-19 20:51 d——– C:\Netgear
2008-02-16 23:48 . 2008-02-16 23:48 d——– C:\WINDOWS\Wireless

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-11 06:26 1,566 —-a-w C:\Documents and Settings\Jesterex\Application Data\wklnhst.dat
2008-03-10 21:01 ——— d—–w C:\Documents and Settings\Jesterex\Application Data\LimeWire
2008-03-10 18:39 ——— d—–w C:\Program Files\McAfee
2008-03-09 07:28 ——— d—–w C:\Program Files\Google
2008-03-09 07:26 ——— d—–w C:\Program Files\Common Files\Stardock
2008-03-08 00:59 ——— d—–w C:\Documents and Settings\Jesterex\Application Data\Hamachi
2008-03-07 15:01 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-05 14:54 430,080 ——w C:\WINDOWS\Fonts\Setup.exe
2008-03-04 23:21 316,928 —-a-w C:\WINDOWS\Fonts\rar.exe
2008-03-04 15:29 ——— d—–w C:\Program Files\YVD
2008-03-03 00:24 ——— d—–w C:\Program Files\Java
2008-03-01 05:11 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-29 16:30 3,145,216 —-a-w C:\WINDOWS\system32\logonuiX.exe
2008-02-28 04:31 ——— d—–w C:\Program Files\MSN Messenger
2008-02-21 15:05 ——— d—–w C:\Program Files\AIM6
2008-02-21 15:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-21 15:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-17 22:01 ——— d—–w C:\Program Files\Pcsx2_0.9.4
2008-02-09 20:56 ——— d—–w C:\Program Files\QuickTime
2008-02-03 03:14 ——— d—–w C:\Program Files\World of Warcraft
2008-01-26 05:36 ——— d—–w C:\Documents and Settings\Jesterex\Application Data\InstallShield Installation Information
2008-01-26 05:22 ——— d—–w C:\Program Files\Unreal Tournament 3
2008-01-26 05:22 ——— d—–w C:\Program Files\AGEIA Technologies
2008-01-24 01:28 ——— d—–w C:\Program Files\2nd Story Software
2008-01-15 05:48 ——— d—–w C:\Program Files\DivX
2008-01-11 05:53 44,544 —-a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-09 11:18 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2008-01-09 11:18 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2008-01-09 11:18 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2008-01-09 11:18 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2008-01-09 11:16 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-01-09 11:16 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2008-01-09 11:16 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2008-01-09 11:16 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2008-01-09 11:16 682,496 —-a-w C:\WINDOWS\system32\DivX.dll
2008-01-09 11:16 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2007-12-19 23:01 347,136 —-a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 ——w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-14 19:32 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
.

((((((((((((((((((((((((((((( snapshot@2008-03-08_23.12.15.15 )))))))))))))))))))))))))))))))))))))))))
.
- 2000-08-31 16:00:00 163,328 —-a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2000-08-31 15:00:00 163,328 —-a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2006-03-03 16:07:02 143,360 —-a-w C:\WINDOWS\LastGood.Tmp\system32\dunzip32.dll
+ 2004-08-04 10:00:00 23,040 —-a-w C:\WINDOWS\LastGood.Tmp\system32\psapi.dll
- 2000-08-31 16:00:00 28,160 —-a-w C:\WINDOWS\Nircmd.exe
+ 2000-08-31 15:00:00 28,160 —-a-w C:\WINDOWS\Nircmd.exe
- 2007-06-25 22:54:44 71,496 —-a-w C:\WINDOWS\system32\drivers\mfeavfk.sys
+ 2007-07-24 14:40:36 79,304 —-a-w C:\WINDOWS\system32\drivers\mfeavfk.sys
- 2007-06-25 17:57:10 34,184 —-a-w C:\WINDOWS\system32\drivers\mfebopk.sys
+ 2007-07-21 16:08:24 35,240 —-a-w C:\WINDOWS\system32\drivers\mfebopk.sys
- 2008-02-06 17:51:44 171,400 —-a-w C:\WINDOWS\system32\drivers\mfehidk.sys
+ 2007-07-21 16:08:24 201,288 —-a-w C:\WINDOWS\system32\drivers\mfehidk.sys
- 2007-06-25 17:57:24 32,008 —-a-w C:\WINDOWS\system32\drivers\mferkdk.sys
+ 2007-07-24 19:02:36 33,800 —-a-w C:\WINDOWS\system32\drivers\mferkdk.sys
- 2007-06-25 17:57:28 37,480 —-a-w C:\WINDOWS\system32\drivers\mfesmfk.sys
+ 2007-07-21 16:08:24 40,488 —-a-w C:\WINDOWS\system32\drivers\mfesmfk.sys
- 2007-03-02 21:16:52 109,608 —-a-w C:\WINDOWS\system32\drivers\Mpfp.sys
+ 2007-07-13 16:20:24 113,952 —-a-w C:\WINDOWS\system32\drivers\Mpfp.sys
- 2006-03-03 16:07:02 143,360 —-a-w C:\WINDOWS\system32\dunzip32.dll
+ 2006-03-03 18:07:02 143,360 —-a-w C:\WINDOWS\system32\dunzip32.dll
+ 2005-05-24 19:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 22:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 22:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2007-11-21 00:04:14 218,496 —-a-w C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe
- 2007-09-20 04:44:32 48,749 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2008-03-10 21:00:16 74,137 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
- 2008-02-04 23:09:46 18,214,008 —-a-w C:\WINDOWS\system32\MRT.exe
+ 2008-03-05 16:30:54 19,148,408 —-a-w C:\WINDOWS\system32\MRT.exe
- 2008-03-09 06:51:36 53,436 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-03-10 03:01:46 53,436 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-03-09 06:51:36 381,692 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-03-10 03:01:46 381,692 —-a-w C:\WINDOWS\system32\perfh009.dat
- 2000-08-31 16:00:00 161,792 —-a-w C:\WINDOWS\system32\swreg.exe
+ 2000-08-31 15:00:00 161,792 —-a-w C:\WINDOWS\system32\swreg.exe
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 09:15 50528]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-03-10 13:59 287040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-05-27 12:21 8429568]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 08:20 282624 C:\WINDOWS\stsystra.exe]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonui.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtusttr]
vtusttr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R0 DigiFilter;DigiFilter;C:\WINDOWS\system32\drivers\DigiFilt.sys [2006-11-13 21:38]
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 08:35]
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2007-05-17 14:45]
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2006-02-14 21:40]
S2 0052481205329009mcinstcleanup;McAfee Application Installer Cleanup (0052481205329009);C:\WINDOWS\TEMP\005248~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S3 iLokDrvr;iLok;C:\WINDOWS\system32\DRIVERS\iLokDrvr.sys [2006-10-05 17:06]
S4 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38]

.
Contents of the 'Scheduled Tasks' folder
"2008-03-06 23:45:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-12 12:55:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-15 09:00:01 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-03-01 09:00:01 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2007-10-30 16:18:12 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_LifeExp_exe.job"
- C:\Program Files\Microsoft LifeCam\LifeExp.exe
"2007-10-30 15:55:57 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_setup_exe.job"
- E:\setup.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-12 06:30:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\ArcSoft\PhotoImpression 5\share\pihook.dll
-> C:\WINDOWS\system32\DLAAPI_W.DLL
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWUpdChk.exe
.
**************************************************************************
.
Completion time: 2008-03-12 6:37:14 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-12 13:37:11
ComboFix2.txt 2008-03-10 03:02:57
ComboFix3.txt 2008-03-09 07:12:37
.
2008-03-11 21:01:23 — E O F —

NEW HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:39:56 AM, on 3/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\imapi.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live Toolbar\msn_sl.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…html?p=ZRfox000
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: vtusttr - vtusttr.dll (file missing)
O23 - Service: McAfee Application Installer Cleanup (0052481205329009) (0052481205329009mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\005248~1.EXE (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 6197 bytes
Hi Sonic4EVA,
We got us a stubborn one:
Lets try it again
NEXT:
1. Please open Notepad
Click Start , then Run
Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:
KillAll::
File::
C:\WINDOWS\pix_office_wall
C:\Documents and Settings\Jesterex\Application Data\wklnhst.dat

Folder::
C:\WINDOWS\system32\iDlo18
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtusttr]
did you get a chance to do this :

re-enable your spyware doctor
Now try your Spyware Doctor scan.
1. Click the "Settings" button on the left side of the Spyware Doctor window.

2. Underneath "Pick a category", choose "Log Settings".

3. Underneath the checkboxes you should see several log file entries noted by the date/time of the entry.
Post a new HJT log and report on scan results as well, along with ComboFix.txt please.



Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Next, re-enable all the programs that you disabled prior to running ComboFix.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Good luck mschroe919
lol who's stubborn? me or the virus? anyways… the spyware doc i have is only the trial version so i didn't find the logs that you requested. I was successful in completing the combofix and hjt logs… so here goes!

COMBOFIX

ComboFix 08-03-08.2 - Jesterex 2008-03-12 15:37:15.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1641 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jesterex\Desktop\CFScript.txt.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Documents and Settings\Jesterex\Application Data\wklnhst.dat
C:\WINDOWS\pix_office_wall
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Jesterex\Application Data\wklnhst.dat
C:\WINDOWS\system32\iDlo18

.
((((((((((((((((((((((((( Files Created from 2008-02-12 to 2008-03-12 )))))))))))))))))))))))))))))))
.

2008-03-12 06:36 . 2008-03-12 06:36 d——– C:\WINDOWS\LastGood.Tmp
2008-03-10 14:01 . 2008-03-10 14:01 d——– C:\Program Files\LimeWire
2008-03-10 13:59 . 2008-03-10 13:59 d——– C:\Program Files\DNA
2008-03-10 13:59 . 2008-03-10 13:59 d——– C:\Program Files\BitTorrent
2008-03-10 13:59 . 2008-03-12 15:31 d——– C:\Documents and Settings\Jesterex\Application Data\DNA
2008-03-10 13:59 . 2008-03-10 18:47 d——– C:\Documents and Settings\Jesterex\Application Data\BitTorrent
2008-03-09 20:05 . 2008-03-09 20:05 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-03-09 20:05 . 2008-03-09 20:05 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-09 00:27 . 2008-03-09 00:27 2,560 –a—— C:\WINDOWS\_MSRSTRT.EXE
2008-03-08 23:50 . 2008-03-08 23:50 d——– C:\Program Files\Sigmatel
2008-03-08 23:50 . 2006-07-24 08:20 1,052,672 –a—— C:\WINDOWS\system32\stlang.dll
2008-03-08 23:50 . 2006-07-24 08:20 282,624 –a—— C:\WINDOWS\stsystra.exe
2008-03-08 07:55 . 2007-09-05 17:23 d——– C:\Documents and Settings\Administrator\Application Data\Roxio
2008-03-08 07:55 . 2007-09-05 17:17 d——– C:\Documents and Settings\Administrator\Application Data\GTek
2008-03-08 07:55 . 2007-09-05 17:22 d——– C:\Documents and Settings\Administrator\Application Data\Creative
2008-03-07 18:08 . 2008-03-07 18:08 d——– C:\Program Files\Trend Micro
2008-03-07 08:01 . 2008-03-07 08:01 d——– C:\Program Files\Lavasoft
2008-03-07 08:01 . 2008-03-07 08:03 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-07 07:52 . 2008-03-09 19:52 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-07 07:52 . 2007-12-10 15:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-07 07:52 . 2007-12-10 15:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-07 07:52 . 2008-02-01 13:55 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-07 07:52 . 2007-12-10 15:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-03-07 07:51 . 2008-03-07 07:55 d——– C:\Program Files\Spyware Doctor
2008-03-07 07:51 . 2008-03-07 07:51 d——– C:\Documents and Settings\Jesterex\Application Data\PC Tools
2008-03-06 14:46 . 2008-03-06 14:46 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-06 14:34 . 2008-03-06 19:36 d——– C:\VundoFix Backups
2008-03-05 22:57 . 2008-03-05 22:57 d——– C:\Documents and Settings\Jesterex\Application Data\TrojanHunter
2008-03-05 22:55 . 2008-03-09 00:26 d——– C:\Program Files\TrojanHunter 4.6
2008-03-05 22:48 . 2008-03-05 22:48 d——– C:\Program Files\Security Task Manager
2008-03-05 22:48 . 2008-03-05 22:54 d——– C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-03-03 12:50 . 2008-03-03 12:50 d——– C:\Program Files\Common Files\Adobe
2008-03-02 20:00 . 2008-03-03 12:50 d——– C:\Program Files\Common Files\Adobe(2)
2008-03-02 17:42 . 2008-03-02 17:43 d——– C:\Program Files\TGTSoft
2008-03-02 17:39 . 2008-03-03 12:50 d——– C:\Program Files\iPod Music Converter
2008-03-02 17:14 . 2008-03-09 00:00 d——– C:\Temp
2008-03-02 16:56 . 2008-03-02 16:56 d——– C:\Program Files\Free iPod Video Converter
2008-03-02 16:56 . 2004-05-25 18:06 417,792 –a—— C:\WINDOWS\system32\ac3filter.ax
2008-03-02 16:56 . 2005-02-27 22:48 356,352 –a—— C:\WINDOWS\system32\RealMediaSplitter.ax
2008-03-02 16:56 . 2004-01-10 18:02 258,048 –a—— C:\WINDOWS\system32\GplMpgDec.ax
2008-02-29 22:12 . 2005-11-13 23:40 89,360 –a—— C:\WINDOWS\system32\VB5DB.DLL
2008-02-29 22:11 . 2008-02-29 22:23 d——– C:\Unreal Anthology
2008-02-29 22:11 . 1997-07-19 18:01 118,781 –a—— C:\WINDOWS\system32\TABCTL32.ocx
2008-02-29 22:11 . 1998-01-24 04:39 110,725 –a—— C:\WINDOWS\system32\RICHTX32.ocx
2008-02-29 22:11 . 1995-07-26 02:00 98,588 –a—— C:\WINDOWS\system32\THREED32.ocx
2008-02-29 22:11 . 1995-07-26 02:00 48,640 –a—— C:\WINDOWS\system32\GRID32.ocx
2008-02-29 22:11 . 1997-01-16 11:11 44,831 –a—— C:\WINDOWS\system32\PICCLP32.ocx
2008-02-29 22:11 . 1995-07-26 02:00 43,502 –a—— C:\WINDOWS\system32\MSOUTL32.ocx
2008-02-29 19:14 . 2008-03-06 14:41 d——– C:\Program Files\Microsoft IntelliType Pro
2008-02-29 19:14 . 2008-02-29 19:14 d——– C:\Program Files\Microsoft IntelliPoint
2008-02-29 09:30 . 2008-02-29 09:30 d——– C:\WINDOWS\pix_office_wall
2008-02-29 09:27 . 2008-02-29 09:27 0 ——— C:\WINDOWS\WB.ini
2008-02-27 21:30 . 2008-02-27 21:30 d–hsc— C:\Program Files\Common Files\WindowsLiveInstaller
2008-02-27 21:29 . 2008-02-27 21:30 d——– C:\Program Files\Windows Live
2008-02-27 21:29 . 2008-02-27 21:29 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-21 16:50 . 2008-02-21 16:50 d——– C:\Program Files\iTunes
2008-02-21 16:50 . 2008-02-21 16:50 d——– C:\Program Files\iPod
2008-02-21 08:04 . 2008-02-21 08:04 d——– C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-02-20 16:51 . 2008-02-20 16:51 d——– C:\Program Files\support.com
2008-02-20 16:51 . 2008-02-20 16:51 d——– C:\Documents and Settings\All Users\Application Data\Support.com
2008-02-19 20:42 . 2008-02-19 20:51 d——– C:\Netgear
2008-02-16 23:48 . 2008-02-16 23:48 d——– C:\WINDOWS\Wireless

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-10 21:01 ——— d—–w C:\Documents and Settings\Jesterex\Application Data\LimeWire
2008-03-10 18:39 ——— d—–w C:\Program Files\McAfee
2008-03-09 07:28 ——— d—–w C:\Program Files\Google
2008-03-09 07:26 ——— d—–w C:\Program Files\Common Files\Stardock
2008-03-08 00:59 ——— d—–w C:\Documents and Settings\Jesterex\Application Data\Hamachi
2008-03-07 15:01 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-05 14:54 430,080 ——w C:\WINDOWS\Fonts\Setup.exe
2008-03-04 23:21 316,928 —-a-w C:\WINDOWS\Fonts\rar.exe
2008-03-04 15:29 ——— d—–w C:\Program Files\YVD
2008-03-03 00:24 ——— d—–w C:\Program Files\Java
2008-03-01 05:11 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-28 04:31 ——— d—–w C:\Program Files\MSN Messenger
2008-02-21 15:05 ——— d—–w C:\Program Files\AIM6
2008-02-21 15:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-21 15:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-17 22:01 ——— d—–w C:\Program Files\Pcsx2_0.9.4
2008-02-09 20:56 ——— d—–w C:\Program Files\QuickTime
2008-02-03 03:14 ——— d—–w C:\Program Files\World of Warcraft
2008-01-26 05:36 ——— d—–w C:\Documents and Settings\Jesterex\Application Data\InstallShield Installation Information
2008-01-26 05:22 ——— d—–w C:\Program Files\Unreal Tournament 3
2008-01-26 05:22 ——— d—–w C:\Program Files\AGEIA Technologies
2008-01-24 01:28 ——— d—–w C:\Program Files\2nd Story Software
2008-01-15 05:48 ——— d—–w C:\Program Files\DivX
.

((((((((((((((((((((((((((((( snapshot_2008-03-12_ 6.36.52.56 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-08 22:35:58 16,384 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-03-12 22:35:21 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-03-08 22:35:58 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-03-12 22:35:21 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-03-08 22:35:58 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-03-12 22:35:21 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 09:15 50528]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-03-10 13:59 287040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-05-27 12:21 8429568]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 08:20 282624 C:\WINDOWS\stsystra.exe]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonui.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R0 DigiFilter;DigiFilter;C:\WINDOWS\system32\drivers\DigiFilt.sys [2006-11-13 21:38]
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 08:35]
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2007-05-17 14:45]
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2006-02-14 21:40]
S2 0052481205329009mcinstcleanup;McAfee Application Installer Cleanup (0052481205329009);C:\WINDOWS\TEMP\005248~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S3 iLokDrvr;iLok;C:\WINDOWS\system32\DRIVERS\iLokDrvr.sys [2006-10-05 17:06]
S4 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38]

*Newly Created Service* - 0052481205329009MCINSTCLEANUP
.
Contents of the 'Scheduled Tasks' folder
"2008-03-06 23:45:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-12 21:55:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-02-15 09:00:01 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-03-01 09:00:01 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2007-10-30 16:18:12 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_LifeExp_exe.job"
- C:\Program Files\Microsoft LifeCam\LifeExp.exe
"2007-10-30 15:55:57 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_setup_exe.job"
- E:\setup.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-12 15:40:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\ArcSoft\PhotoImpression 5\share\pihook.dll
-> C:\WINDOWS\system32\DLAAPI_W.DLL
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\imapi.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
.
**************************************************************************
.
Completion time: 2008-03-12 15:45:11 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-12 22:45:08
ComboFix2.txt 2008-03-12 13:37:15
ComboFix3.txt 2008-03-10 03:02:57
ComboFix4.txt 2008-03-09 07:12:37
.
2008-03-11 21:01:23 — E O F —

HiJackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:51:11 PM, on 3/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Spyware Doctor\pctsGui.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…html?p=ZRfox000
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: McAfee Application Installer Cleanup (0052481205329009) (0052481205329009mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\005248~1.EXE (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 6549 bytes
Hi onic4EVA

lol who's stubborn? me or the virus?


Of couse it is the Virus, your doing great we are almost done.

I will be back soon. By the way how is your pc behaving?
mschroe919

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI