This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] AntispywareXP 2009

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My machine has malware: AntispywareXP 2009. I run Firewall Comodo. And somehow, I figure, I must have given this "thing" permission to install. GRRRRRR, even though for each of the permission questions Comodo asked, I blocked! GRRRRR!!

It continuously launches the file called "Antispyware WindowsXP 2009". This virus is attacking all of my .exe files. I can't get anything to run. That is, I cannot even get HJT to run. I cannot even get on the net, my Firewall has been hijacked & my antivirus has been shut down. I am currently on another hard drive to get here. I have done a search for this problem on "What the tech" & found:

http://forums.whatthetech.com/I_got_an_ugl…iSpywareXP+2009

I implemented the first portion of instructions from the above:

1.Click Start.
2.Point to All Programs.
3.Point to Accessories.
4.Point to System Tools.
5.Click System Restore.
6.Follow the instructions on the wizard.

The machine restored [to 5 days earlier], but AntispywareXP 2009 is still there!

I tried renaming HijackThis.exe to Hijackthis.com. Nope. It won't run.

The next instruction shows to download Malwarebytes. I have downloaded Mbam. However, from this point I need assistance please.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hello LD,
My internet Browser wasn't working. After running mbam, I uninstalled my Browser [Firefox] & reinstalled it. Yay, success!

Here is my mbam log & my HJT log file:
===============================================================
Malwarebytes' Anti-Malware 1.30
Database version: 1306
Windows 5.1.2600 Service Pack 3

10/27/2008 2:36:35 PM
mbam-log-2008-10-27 (14-36-35).txt

Scan type: Quick Scan
Objects scanned: 47045
Time elapsed: 4 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 1
Files Infected: 22

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\antispywarexp2009 (Rogue.AntispywareXP) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\antispywarexp2009 (Rogue.AntispywareXP) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\brastk (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\ -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\ -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\AntiSpywareXP2009 (Rogue.AntispywareXP) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\karna.dat (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\karna.dat (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Program Files\AntiSpywareXP2009\Uninstall.exe (Rogue.AntispywareXP) -> Quarantined and deleted successfully.
C:\Documents and Settings\Admin\Desktop\AntiSpywareXP2009.lnk (Rogue.Antispyware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\AntiSpywareXP2009.lnk (Rogue.Antispyware) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\delself.bat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\beep.sys (Fake.Beep.Sys) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dllcache\beep.sys (Fake.Beep.Sys) -> Quarantined and deleted successfully.
C:\WINDOWS\brastk.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\_scui.cpl (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wini10802.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\brastk.exe (Trojan.FakeAlert) -> Delete on reboot.
C:\WINDOWS\system32\TDSScubv.log (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\TDSShrxm.dll (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\TDSSlxwp.dll (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\TDSSnmxh.log (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\TDSSoiqt.dll (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\TDSSrhyp.dll (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\TDSSvkql.dll (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\TDSSxfum.dll (Rootkit.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\TDSSmqlt.sys (Rootkit.Agent) -> Delete on reboot.

=============================================================================

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:55:38 PM, on 10/27/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\MSTMON_S.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/rlidOfficeUpdate?clid=1033
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb126\SearchSettings.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [KONICA MINOLTA magicolor 2400W STD] C:\WINDOWS\system32\MSTMON_S.EXE STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1143246383000
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143472817734
O20 - AppInit_DLLs: karna.dat
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe (file missing)
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (file missing)
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (file missing)
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Office Source Engine (ose) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (file missing)

–
End of file - 8521 bytes
Lets dig deeper :thumbup:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
Hello LD,

Before running Combofix: Firewall [Comodo] was inoperative; Antivirus [Avast] was showing an error; Many of my executables were no longer operative w/o uninstalling & reinstalling.

Here is the Combofix log & HJT log:
================================================================================
=================


ComboFix 08-10-25.01 - Admin 2008-10-27 19:21:48.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.162 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\Downloaded Program Files\setup.inf

.
((((((((((((((((((((((((( Files Created from 2008-09-27 to 2008-10-27 )))))))))))))))))))))))))))))))
.

2008-10-27 19:10 . 2008-10-27 19:10 d——– C:\Program Files\WordWeb
2008-10-27 18:55 . 2008-10-27 18:55 d——– C:\Program Files\Trend Micro
2008-10-27 14:23 . 2008-10-27 14:23 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-27 14:23 . 2008-10-27 14:23 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-27 14:23 . 2008-10-27 14:23 d——– C:\Documents and Settings\Admin\Application Data\Malwarebytes
2008-10-27 14:23 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-27 14:23 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-27 01:13 . 2008-10-27 01:13 d——– C:\Documents and Settings\Admin\Application Data\SoftwareDetectionScripts
2008-10-27 01:03 . 2008-10-27 01:03 16,534 –a—— C:\WINDOWS\fokoquq.db
2008-10-27 01:03 . 2008-10-27 01:03 15,392 –a—— C:\Documents and Settings\Admin\Application Data\ehyhyvupeq.bat
2008-10-27 01:03 . 2008-10-27 01:03 10,913 –a—— C:\WINDOWS\nuros.reg
2008-10-27 01:03 . 2008-10-27 01:03 10,533 –a—— C:\WINDOWS\rocepezyf.scr
2008-10-27 01:00 . 2008-10-27 01:00 19,615 –a—— C:\WINDOWS\zyjam.db
2008-10-27 01:00 . 2008-10-27 01:00 17,860 –a—— C:\WINDOWS\system32\zihilewube.inf
2008-10-27 01:00 . 2008-10-27 01:00 16,728 –a—— C:\WINDOWS\urohofadaj.dl
2008-10-27 01:00 . 2008-10-27 01:00 16,179 –a—— C:\WINDOWS\system32\dyduvys._dl
2008-10-27 01:00 . 2008-10-27 01:00 15,570 –a—— C:\WINDOWS\uzofy.bin
2008-10-27 01:00 . 2008-10-27 01:00 15,037 –a—— C:\Documents and Settings\All Users\Application Data\esurexevif.bin
2008-10-27 01:00 . 2008-10-27 01:00 14,801 –a—— C:\Documents and Settings\Admin\Application Data\ucohitu.pif
2008-10-27 01:00 . 2008-10-27 01:00 13,446 –a—— C:\WINDOWS\system32\uloc.scr
2008-10-27 01:00 . 2008-10-27 01:00 13,280 –a—— C:\WINDOWS\system32\ycalyn.reg
2008-10-27 00:57 . 2008-10-27 00:57 19,277 –a—— C:\WINDOWS\fiko.pif
2008-10-27 00:57 . 2008-10-27 00:57 18,841 –a—— C:\Documents and Settings\Admin\Application Data\qiriq.dat
2008-10-27 00:57 . 2008-10-27 00:57 17,788 –a—— C:\WINDOWS\enyqero.dat
2008-10-27 00:57 . 2008-10-27 00:57 15,777 –a—— C:\WINDOWS\ebogasajur._sy
2008-10-27 00:57 . 2008-10-27 00:57 15,596 –a—— C:\Documents and Settings\Admin\Application Data\tegaz.exe
2008-10-27 00:57 . 2008-10-27 00:57 15,406 –a—— C:\Documents and Settings\Admin\Application Data\xurymeby.reg
2008-10-27 00:57 . 2008-10-27 00:57 13,617 –a—— C:\WINDOWS\system32\pefy.scr
2008-10-27 00:33 . 2008-10-27 00:33 44,032 –a—— C:\WINDOWS\system32\av.dat
2008-10-27 00:33 . 2008-10-27 00:33 164 –a—— C:\WINDOWS\system32\TDSSmtvd.dat
2008-10-26 20:39 . 2008-10-27 06:03 d——– C:\Program Files\CDBurnerXP
2008-10-23 19:29 . 2008-10-15 12:34 337,408 —–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-14 19:10 . 2008-09-08 06:41 333,824 —–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-14 19:03 . 2008-08-14 06:11 2,189,184 —–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-14 19:03 . 2008-08-14 06:09 2,145,280 —–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-14 19:03 . 2008-08-14 05:33 2,066,048 —–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-14 19:03 . 2008-08-14 05:33 2,023,936 —–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-14 19:03 . 2008-09-15 08:12 1,846,400 —–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-09 06:17 . 2008-10-09 06:17 10,839 –ah—– C:\WINDOWS\system32\MSTMON_S.GID

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-27 23:26 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-27 05:20 ——— d—–w C:\Program Files\Yahoo!
2008-10-27 05:08 ——— d—–w C:\Program Files\WinZip-7
2008-10-27 05:08 ——— d—–w C:\Program Files\Winamp
2008-10-27 05:08 ——— d—–w C:\Program Files\Verizon
2008-10-27 05:08 ——— d—–w C:\Program Files\QuickTime
2008-10-27 05:07 ——— d—–w C:\Program Files\Lavasoft
2008-10-27 05:07 ——— d—–w C:\Program Files\Kodak
2008-10-27 05:06 ——— d—–w C:\Program Files\Java
2008-10-27 05:06 ——— d—–w C:\Program Files\Google
2008-10-27 05:05 ——— d—–w C:\Program Files\Common Files\Ahead
2008-10-27 02:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-27 00:56 ——— d—–w C:\Documents and Settings\Admin\Application Data\Ahead
2008-10-26 19:08 ——— d—–w C:\Documents and Settings\Admin\Application Data\LimeWire
2008-10-13 11:20 ——— d—–w C:\Documents and Settings\Admin\Application Data\SlimBrowser
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-06 19:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-06 04:47 ——— d—–w C:\Documents and Settings\Admin\Application Data\Stellarium
2008-01-22 23:10 47,360 —-a-w C:\Documents and Settings\Admin\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-03-09 7561216]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-03-09 86016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"KONICA MINOLTA magicolor 2400W STD"="C:\WINDOWS\system32\MSTMON_S.EXE" [2005-06-22 184320]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 282624]
"SecurDisc"="C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-10-26 292152]
"VerizonServicepoint.exe"="C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" [2007-05-11 2061816]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-08-03 36352]
"nwiz"="nwiz.exe" [2006-03-09 C:\WINDOWS\system32\nwiz.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-18 124400]
WordWeb.lnk - C:\Program Files\WordWeb\wweb32.exe [2008-10-27 44384]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSVIDEO5"= concord.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-07-21 87056]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-07-21 24208]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 MLPTDR_Q;MLPTDR_Q;C:\WINDOWS\system32\MLPTDR_Q.sys [2003-07-22 18848]
S2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [ ]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{049cb996-a465-11db-a634-00e04cb779fd}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2008-10-27 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe []
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Yahoo! Pager - C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
HKCU-Run-ccleaner - C:\Program Files\CCleaner\CCleaner.exe
HKLM-Run-NeroFilterCheck - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
HKLM-Run-Adobe Reader Speed Launcher - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
HKLM-Run-COMODO Firewall Pro - C:\Program Files\COMODO\Firewall\cfp.exe


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\isro5pa4.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://mail.yahoo.com/?.intl=us
FF -: plugin - C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll
FF -: plugin - C:\Program Files\Google\Google Updater\2.2.1202.1501\npCIDetect11.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-27 19:26:23
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDSSserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSmqlt.sys"
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
.
**************************************************************************
.
Completion time: 2008-10-27 19:30:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-27 23:29:59
ComboFix2.txt 2008-01-25 01:17:36

Pre-Run: 16,679,882,752 bytes free
Post-Run: 16,677,761,024 bytes free

166 — E O F — 2008-10-24 00:06:42

================================================================================
======================

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:32:15 PM, on 10/27/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\MSTMON_S.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\WordWeb\wweb32.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/rlidOfficeUpdate?clid=1033
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [KONICA MINOLTA magicolor 2400W STD] C:\WINDOWS\system32\MSTMON_S.EXE STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1143246383000
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143472817734
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe (file missing)
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (file missing)
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (file missing)
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Office Source Engine (ose) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (file missing)

–
End of file - 7863 bytes
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
C:\WINDOWS\fokoquq.db
C:\Documents and Settings\Admin\Application Data\ehyhyvupeq.bat
C:\WINDOWS\nuros.reg
C:\WINDOWS\rocepezyf.scr
C:\WINDOWS\zyjam.db
C:\WINDOWS\system32\zihilewube.inf
C:\WINDOWS\urohofadaj.dl
C:\WINDOWS\system32\dyduvys._dl
C:\WINDOWS\uzofy.bin
C:\Documents and Settings\All Users\Application Data\esurexevif.bin
C:\Documents and Settings\Admin\Application Data\ucohitu.pif
C:\WINDOWS\system32\uloc.scr
C:\WINDOWS\system32\ycalyn.reg
C:\WINDOWS\fiko.pif
C:\Documents and Settings\Admin\Application Data\qiriq.dat
C:\WINDOWS\enyqero.dat
C:\WINDOWS\ebogasajur._sy
C:\Documents and Settings\Admin\Application Data\tegaz.exe
C:\Documents and Settings\Admin\Application Data\xurymeby.reg
C:\WINDOWS\system32\pefy.scr
C:\WINDOWS\system32\av.dat
C:\WINDOWS\system32\TDSSmtvd.dat

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
I am on a neighbor machine operating on a common router/modem. My machine, running Combofix per your last instruction, has been idle with the blue box for about 40 minutes +. The header bar reads "Find 3M". The text in the blue background box reads: Preparing log report. Do not run any programs until Combofix has finished Access is denied. It seems as though this is too much time. Is my machine hung?
I'd try using Alt/Ctrl/Del and end the process. Did you disconnect from the web and disable any anti-virus programs? if it doesn't finish, reboot and try the fix again.
Hi LD,
Did the Ctrl-Alt-Del & 86'd out of it. Shut down, as no applications were available [Desktop was free of icons]. Rebooted. Re-ran Combofix per last instruction.

Anti-virus program I had uninstalled already. It wasn't working anyways, & figured I would re-install later.

I had not disconnected from the net.

Combofix attempted to install RECOVERY CONSOLE. It failed.

Here is Combofix log & HJT log
================================================================================
===========
ComboFix 08-10-25.01 - Admin 2008-10-27 21:35:19.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.254 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Admin\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Documents and Settings\Admin\Application Data\ehyhyvupeq.bat
C:\Documents and Settings\Admin\Application Data\qiriq.dat
C:\Documents and Settings\Admin\Application Data\tegaz.exe
C:\Documents and Settings\Admin\Application Data\ucohitu.pif
C:\Documents and Settings\Admin\Application Data\xurymeby.reg
C:\Documents and Settings\All Users\Application Data\esurexevif.bin
C:\WINDOWS\ebogasajur._sy
C:\WINDOWS\enyqero.dat
C:\WINDOWS\fiko.pif
C:\WINDOWS\fokoquq.db
C:\WINDOWS\nuros.reg
C:\WINDOWS\rocepezyf.scr
C:\WINDOWS\system32\av.dat
C:\WINDOWS\system32\dyduvys._dl
C:\WINDOWS\system32\pefy.scr
C:\WINDOWS\system32\TDSSmtvd.dat
C:\WINDOWS\system32\uloc.scr
C:\WINDOWS\system32\ycalyn.reg
C:\WINDOWS\system32\zihilewube.inf
C:\WINDOWS\urohofadaj.dl
C:\WINDOWS\uzofy.bin
C:\WINDOWS\zyjam.db
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\Documents and Settings\Admin\Application Data\ehyhyvupeq.bat
C:\Documents and Settings\Admin\Application Data\qiriq.dat
C:\Documents and Settings\Admin\Application Data\tegaz.exe
C:\Documents and Settings\Admin\Application Data\ucohitu.pif
C:\Documents and Settings\Admin\Application Data\xurymeby.reg
C:\Documents and Settings\All Users\Application Data\esurexevif.bin
C:\WINDOWS\ebogasajur._sy
C:\WINDOWS\enyqero.dat
C:\WINDOWS\fiko.pif
C:\WINDOWS\fokoquq.db
C:\WINDOWS\nuros.reg
C:\WINDOWS\rocepezyf.scr
C:\WINDOWS\system32\av.dat
C:\WINDOWS\system32\dyduvys._dl
C:\WINDOWS\system32\pefy.scr
C:\WINDOWS\system32\TDSSmtvd.dat
C:\WINDOWS\system32\uloc.scr
C:\WINDOWS\system32\ycalyn.reg
C:\WINDOWS\system32\zihilewube.inf
C:\WINDOWS\urohofadaj.dl
C:\WINDOWS\uzofy.bin
C:\WINDOWS\zyjam.db

.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-28 )))))))))))))))))))))))))))))))
.

2008-10-27 19:53 . 2008-10-27 19:53 d——– C:\Program Files\Washer
2008-10-27 19:10 . 2008-10-27 19:10 d——– C:\Program Files\WordWeb
2008-10-27 18:55 . 2008-10-27 18:55 d——– C:\Program Files\Trend Micro
2008-10-27 14:23 . 2008-10-27 14:23 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-27 14:23 . 2008-10-27 14:23 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-27 14:23 . 2008-10-27 14:23 d——– C:\Documents and Settings\Admin\Application Data\Malwarebytes
2008-10-27 14:23 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-27 14:23 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-27 01:13 . 2008-10-27 01:13 d——– C:\Documents and Settings\Admin\Application Data\SoftwareDetectionScripts
2008-10-26 20:39 . 2008-10-27 06:03 d——– C:\Program Files\CDBurnerXP
2008-10-23 19:29 . 2008-10-15 12:34 337,408 —–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-14 19:10 . 2008-09-08 06:41 333,824 —–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-14 19:03 . 2008-08-14 06:11 2,189,184 —–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-14 19:03 . 2008-08-14 06:09 2,145,280 —–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-14 19:03 . 2008-08-14 05:33 2,066,048 —–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-14 19:03 . 2008-08-14 05:33 2,023,936 —–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-14 19:03 . 2008-09-15 08:12 1,846,400 —–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-09 06:17 . 2008-10-09 06:17 10,839 –ah—– C:\WINDOWS\system32\MSTMON_S.GID

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-28 01:21 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-28 00:13 ——— d—–w C:\Documents and Settings\Admin\Application Data\Winamp
2008-10-27 23:55 ——— d—–w C:\Program Files\Winamp
2008-10-27 05:20 ——— d—–w C:\Program Files\Yahoo!
2008-10-27 05:08 ——— d—–w C:\Program Files\WinZip-7
2008-10-27 05:08 ——— d—–w C:\Program Files\Verizon
2008-10-27 05:08 ——— d—–w C:\Program Files\QuickTime
2008-10-27 05:07 ——— d—–w C:\Program Files\Lavasoft
2008-10-27 05:07 ——— d—–w C:\Program Files\Kodak
2008-10-27 05:06 ——— d—–w C:\Program Files\Java
2008-10-27 05:06 ——— d—–w C:\Program Files\Google
2008-10-27 05:05 ——— d—–w C:\Program Files\Common Files\Ahead
2008-10-27 02:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-27 00:56 ——— d—–w C:\Documents and Settings\Admin\Application Data\Ahead
2008-10-26 19:08 ——— d—–w C:\Documents and Settings\Admin\Application Data\LimeWire
2008-10-13 11:20 ——— d—–w C:\Documents and Settings\Admin\Application Data\SlimBrowser
2008-09-15 12:12 1,846,400 —-a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-06 19:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-06 04:47 ——— d—–w C:\Documents and Settings\Admin\Application Data\Stellarium
2008-08-26 07:24 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 10:11 2,189,184 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:33 2,066,048 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-01-22 23:10 47,360 —-a-w C:\Documents and Settings\Admin\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"Washer"="C:\Program Files\Washer\washer.exe" [2003-01-13 818688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-03-09 7561216]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-03-09 86016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"KONICA MINOLTA magicolor 2400W STD"="C:\WINDOWS\system32\MSTMON_S.EXE" [2005-06-22 184320]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 282624]
"SecurDisc"="C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-10-26 292152]
"VerizonServicepoint.exe"="C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" [2007-05-11 2061816]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-08-03 36352]
"nwiz"="nwiz.exe" [2006-03-09 C:\WINDOWS\system32\nwiz.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-18 124400]
WordWeb.lnk - C:\Program Files\WordWeb\wweb32.exe [2008-10-27 44384]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSVIDEO5"= concord.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-07-21 87056]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-07-21 24208]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 MLPTDR_Q;MLPTDR_Q;C:\WINDOWS\system32\MLPTDR_Q.sys [2003-07-22 18848]
S2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [ ]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{049cb996-a465-11db-a634-00e04cb779fd}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2008-10-27 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe []
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-27 21:37:41
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSmqlt.sys"
.
Completion time: 2008-10-27 21:39:31
ComboFix-quarantined-files.txt 2008-10-28 01:39:22
ComboFix2.txt 2008-10-27 23:30:08
ComboFix3.txt 2008-01-25 01:17:36

Pre-Run: 16,560,713,728 bytes free
Post-Run: 16,547,082,240 bytes free

173 — E O F — 2008-10-24 00:06:42
================================================================================
===================

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:41:21 PM, on 10/27/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\MSTMON_S.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Washer\washer.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\WordWeb\wweb32.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/rlidOfficeUpdate?clid=1033
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [KONICA MINOLTA magicolor 2400W STD] C:\WINDOWS\system32\MSTMON_S.EXE STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Washer] C:\Program Files\Washer\washer.exe /0
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1143246383000
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143472817734
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe (file missing)
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (file missing)
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (file missing)
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Office Source Engine (ose) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (file missing)

–
End of file - 7919 bytes
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

Driver::
TDSSmqlt

Registry::
[-HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv.sys]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Hello LD,

Question: Windows Recovery Console shows by Combofix as not installed. I do not know what this is. Do I need this? How do I get it?

Here is Combofix log & HJT log:

===========================================
===========================================

ComboFix 08-10-25.01 - Admin 2008-10-27 22:30:55.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.223 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Admin\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-28 )))))))))))))))))))))))))))))))
.

2008-10-27 19:53 . 2008-10-27 19:53 d——– C:\Program Files\Washer
2008-10-27 19:10 . 2008-10-27 19:10 d——– C:\Program Files\WordWeb
2008-10-27 18:55 . 2008-10-27 18:55 d——– C:\Program Files\Trend Micro
2008-10-27 14:23 . 2008-10-27 14:23 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-27 14:23 . 2008-10-27 14:23 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-27 14:23 . 2008-10-27 14:23 d——– C:\Documents and Settings\Admin\Application Data\Malwarebytes
2008-10-27 14:23 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-27 14:23 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-27 01:13 . 2008-10-27 01:13 d——– C:\Documents and Settings\Admin\Application Data\SoftwareDetectionScripts
2008-10-26 20:39 . 2008-10-27 06:03 d——– C:\Program Files\CDBurnerXP
2008-10-23 19:29 . 2008-10-15 12:34 337,408 —–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-14 19:10 . 2008-09-08 06:41 333,824 —–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-14 19:03 . 2008-08-14 06:11 2,189,184 —–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-14 19:03 . 2008-08-14 06:09 2,145,280 —–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-14 19:03 . 2008-08-14 05:33 2,066,048 —–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-14 19:03 . 2008-08-14 05:33 2,023,936 —–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-14 19:03 . 2008-09-15 08:12 1,846,400 —–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-09 06:17 . 2008-10-09 06:17 10,839 –ah—– C:\WINDOWS\system32\MSTMON_S.GID

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"Washer"="C:\Program Files\Washer\washer.exe" [2003-01-13 818688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-03-09 7561216]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-03-09 86016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"KONICA MINOLTA magicolor 2400W STD"="C:\WINDOWS\system32\MSTMON_S.EXE" [2005-06-22 184320]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 282624]
"SecurDisc"="C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-10-26 292152]
"VerizonServicepoint.exe"="C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" [2007-05-11 2061816]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-08-03 36352]
"nwiz"="nwiz.exe" [2006-03-09 C:\WINDOWS\system32\nwiz.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-18 124400]
WordWeb.lnk - C:\Program Files\WordWeb\wweb32.exe [2008-10-27 44384]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSVIDEO5"= concord.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-07-21 87056]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-07-21 24208]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 MLPTDR_Q;MLPTDR_Q;C:\WINDOWS\system32\MLPTDR_Q.sys [2003-07-22 18848]
S2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [ ]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{049cb996-a465-11db-a634-00e04cb779fd}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2008-10-27 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe []
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-27 22:33:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSmqlt.sys"
.
Completion time: 2008-10-27 22:34:49
ComboFix-quarantined-files.txt 2008-10-28 02:34:40
ComboFix2.txt 2008-10-28 01:39:32
ComboFix3.txt 2008-10-27 23:30:08
ComboFix4.txt 2008-01-25 01:17:36

Pre-Run: 16,522,817,536 bytes free
Post-Run: 16,510,001,152 bytes free

99 — E O F — 2008-10-24 00:06:42

===========================================
===========================================

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:35:27 PM, on 10/27/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\MSTMON_S.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Washer\washer.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\WordWeb\wweb32.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/rlidOfficeUpdate?clid=1033
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [KONICA MINOLTA magicolor 2400W STD] C:\WINDOWS\system32\MSTMON_S.EXE STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Washer] C:\Program Files\Washer\washer.exe /0
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1143246383000
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143472817734
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe (file missing)
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (file missing)
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (file missing)
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Office Source Engine (ose) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (file missing)

–
End of file - 7966 bytes
It runs, but: :(
- I have found so much stuff that was trashed, even beyond the exe's not running [Ex: xml's for Movie maker, I had written a bunch; All GONE, & I am still running into more & more areas that were affected.]. Good thing I have all sorts of back-ups!

My biggest concerns:
1- The Comodo firewall no longer behaves as it did. Ex: When I used to attempt to install an app, it would tell me that an app was about to be installed & ask me if it was okay. It no longer asks me anything. I tried to UNinstall it in order to RE-install it. Nope. After I have removed it from the Add/Remove screen & attempt to install it, the message tells me it is already installed & would I like to UNinstall it. A "Yes" answer does not successfully uninstall it.
2- Avast Anti-virus I have done the same: Uninstalled it. Yet, when I run the executable for installation [to reinstall], it appears to run briefly, then produces nothing, almost like it started to run & just disappeared.

My sys-tray shows neither Comodo nor Avast are operating! Is it possible this virus has left just enough stubs [pieces] of those apps behind to create this problem? If I want to run Comodo & if I want to run Avast, might I need to re-format? I hate to even say those words, but at this point, I am recognizing that this may be the only choice.

If I am able to solve the Comodo & Avast problem by installing each successfully & running both, I can handle all other problems. If I am not able to, then I [relenting] will reformat.

Please advise.
Thank you.
Pete
P.S. As I scan the HJT forum postings, I see a number of ppl that are encountering this nasty. And it IS a nasty!
OK, lets see if we can remove all of Comodo and Avast.
Then try the re-install.

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
C:\WINDOWS\system32\drivers\aswSP.sys
C:\WINDOWS\system32\DRIVERS\cmdguard.sys 
C:\WINDOWS\system32\DRIVERS\cmdhlp.sys
C:\windows\system32\drivers\TDSSmqlt.sys
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe


Folder::
C:\Program Files\Alwil Software
C:\Program Files\COMODO

Driver::
aswSP
cmdguard
cmdhlp
TDSSmqlt

Registry::
[-HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv.sys]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Hello LD,

Okee-doke. One down, one remains.

2- Avast Anti-virus: SUCCESS! This installed fine & runs as it has & as it is expected to. :thumbup:

1- Comodo: I have attached a screen capture of the message box that comes up. One attempt to re-install it met with this message box:
"COMODO Firewall Pro is already installed on your system. Do you want to un-install it now?"

Here is my latest Combox Fix Log & HJT log:

ComboFix 08-10-25.01 - Admin 2008-10-30 15:22:41.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.234 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Admin\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\drivers\aswSP.sys
C:\WINDOWS\system32\DRIVERS\cmdguard.sys
C:\WINDOWS\system32\DRIVERS\cmdhlp.sys
C:\windows\system32\drivers\TDSSmqlt.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Alwil Software
C:\Program Files\Alwil Software\Avast4\Aavm4h.dll
C:\Program Files\Alwil Software\Avast4\AavmRpch.dll
C:\Program Files\Alwil Software\Avast4\ashBase.dll
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\ashShell.dll
C:\Program Files\Alwil Software\Avast4\ashTask.dll
C:\Program Files\Alwil Software\Avast4\aswAux.dll
C:\Program Files\Alwil Software\Avast4\aswCmnB.dll
C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll
C:\Program Files\Alwil Software\Avast4\aswCmnS.dll
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.ini
C:\Program Files\Alwil Software\Avast4\ENGLISH\Base.dll
C:\Program Files\Alwil Software\Avast4\ENGLISH\Lang.dll
C:\Program Files\COMODO
C:\Program Files\COMODO\Firewall\cfpinfo.ini
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\drivers\aswSP.sys
C:\WINDOWS\system32\DRIVERS\cmdguard.sys
C:\WINDOWS\system32\DRIVERS\cmdhlp.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ASWSP
——-\Legacy_CMDGUARD
——-\Legacy_CMDHLP
——-\Service_aswSP
——-\Service_cmdGuard
——-\Service_cmdHlp


((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-30 )))))))))))))))))))))))))))))))
.

2008-10-28 10:25 . 2008-10-28 10:25 d——– C:\Program Files\Lavasoft
2008-10-28 10:25 . 2008-10-28 10:25 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-10-28 10:08 . 2008-10-28 10:08 d——– C:\Program Files\FLVPlayer
2008-10-28 08:48 . 2008-10-28 08:49 d——– C:\Program Files\CCleaner
2008-10-28 08:45 . 2008-10-28 08:45 d——– C:\Program Files\Microsoft ActiveSync
2008-10-28 07:29 . 2008-10-28 07:29 16 –a—— C:\WINDOWS\winzip32.ini
2008-10-27 19:53 . 2008-10-27 19:53 d——– C:\Program Files\Washer
2008-10-27 19:10 . 2008-10-27 19:10 d——– C:\Program Files\WordWeb
2008-10-27 18:55 . 2008-10-27 18:55 d——– C:\Program Files\Trend Micro
2008-10-27 14:23 . 2008-10-27 14:23 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-27 14:23 . 2008-10-27 14:23 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-27 14:23 . 2008-10-27 14:23 d——– C:\Documents and Settings\Admin\Application Data\Malwarebytes
2008-10-27 14:23 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-27 14:23 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-27 01:13 . 2008-10-27 01:13 d——– C:\Documents and Settings\Admin\Application Data\SoftwareDetectionScripts
2008-10-26 20:39 . 2008-10-27 06:03 d——– C:\Program Files\CDBurnerXP
2008-10-23 19:29 . 2008-10-15 12:34 337,408 —–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-14 19:10 . 2008-09-08 06:41 333,824 —–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-14 19:03 . 2008-08-14 06:11 2,189,184 —–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-14 19:03 . 2008-08-14 06:09 2,145,280 —–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-14 19:03 . 2008-08-14 05:33 2,066,048 —–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-14 19:03 . 2008-08-14 05:33 2,023,936 —–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-14 19:03 . 2008-09-15 08:12 1,846,400 —–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-09 06:17 . 2008-10-09 06:17 10,839 –ah—– C:\WINDOWS\system32\MSTMON_S.GID
2008-09-12 19:45 . 2008-09-12 19:45 d——– C:\WINDOWS\system32\scripting
2008-09-12 19:44 . 2008-09-12 19:44 d——– C:\WINDOWS\system32\en
2008-09-12 19:44 . 2008-09-12 19:45 d——– C:\WINDOWS\l2schemas
2008-09-12 19:02 . 2008-04-13 20:12 774,144 –a–c— C:\WINDOWS\system32\dllcache\setup_wm.exe
2008-09-12 19:01 . 2008-04-13 20:12 1,306,624 ——— C:\WINDOWS\system32\msxml6.dll
2008-09-12 19:00 . 2003-03-31 08:00 457,607 —–c— C:\WINDOWS\system32\dllcache\mdlib.wmv
2008-09-12 18:59 . 2008-04-13 20:12 695,808 —–c— C:\WINDOWS\system32\dllcache\drmv2clt.dll
2008-09-07 21:37 . 2008-10-26 15:08 d——– C:\Documents and Settings\Admin\Application Data\LimeWire
2008-09-05 23:44 . 2008-09-06 00:47 d——– C:\Documents and Settings\Admin\Application Data\Stellarium

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-30 19:28 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-29 18:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-28 12:48 ——— d—–w C:\Program Files\Yahoo!
2008-10-28 00:13 ——— d—–w C:\Documents and Settings\Admin\Application Data\Winamp
2008-10-27 23:55 ——— d—–w C:\Program Files\Winamp
2008-10-27 05:08 ——— d—–w C:\Program Files\WinZip-7
2008-10-27 05:08 ——— d—–w C:\Program Files\Verizon
2008-10-27 05:08 ——— d—–w C:\Program Files\QuickTime
2008-10-27 05:07 ——— d—–w C:\Program Files\Kodak
2008-10-27 05:06 ——— d—–w C:\Program Files\Java
2008-10-27 05:06 ——— d—–w C:\Program Files\Google
2008-10-27 05:05 ——— d—–w C:\Program Files\Common Files\Ahead
2008-10-27 00:56 ——— d—–w C:\Documents and Settings\Admin\Application Data\Ahead
2008-10-13 11:20 ——— d—–w C:\Documents and Settings\Admin\Application Data\SlimBrowser
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-06 19:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-22 23:10 47,360 —-a-w C:\Documents and Settings\Admin\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((( snapshot@2008-10-27_19.29.28.89 )))))))))))))))))))))))))))))))))))))))))
.
- 2006-11-08 05:01:06 66,048 -c–a-w C:\WINDOWS\ie7\spuninst\ieResetIcons.exe
+ 2007-08-13 22:52:06 66,048 -c–a-w C:\WINDOWS\ie7\spuninst\ieResetIcons.exe
- 2006-11-07 11:26:44 71,680 —-a-w C:\WINDOWS\system32\admparse.dll
+ 2007-08-13 22:39:20 71,680 —-a-w C:\WINDOWS\system32\admparse.dll
- 2006-11-07 11:26:44 71,680 -c—-w C:\WINDOWS\system32\dllcache\admparse.dll
+ 2007-08-13 22:39:20 71,680 -c–a-w C:\WINDOWS\system32\dllcache\admparse.dll
+ 2006-09-23 17:12:50 1,022,976 -c—-w C:\WINDOWS\system32\dllcache\browseui.dll
+ 2007-08-13 22:42:54 17,408 -c—-w C:\WINDOWS\system32\dllcache\corpol.dll
- 2006-11-08 05:03:36 33,792 -c–a-w C:\WINDOWS\system32\dllcache\custsat.dll
+ 2007-08-13 22:54:10 33,792 -c–a-w C:\WINDOWS\system32\dllcache\custsat.dll
- 2006-10-17 19:44:36 60,416 -c–a-w C:\WINDOWS\system32\dllcache\hmmapi.dll
+ 2007-08-13 22:18:02 60,416 -c–a-w C:\WINDOWS\system32\dllcache\hmmapi.dll
- 2006-10-17 20:04:50 69,120 -c–a-w C:\WINDOWS\system32\dllcache\iedw.exe
+ 2007-08-13 22:44:02 69,120 -c–a-w C:\WINDOWS\system32\dllcache\iedw.exe
+ 2007-08-13 22:45:18 78,336 -c—-w C:\WINDOWS\system32\dllcache\ieencode.dll
- 2006-11-08 05:03:36 191,488 -c–a-w C:\WINDOWS\system32\dllcache\iepeers.dll
+ 2007-08-13 22:54:10 191,488 -c–a-w C:\WINDOWS\system32\dllcache\iepeers.dll
- 2006-11-07 11:26:42 55,296 -c—-w C:\WINDOWS\system32\dllcache\iesetup.dll
+ 2007-08-13 22:39:12 55,296 -c–a-w C:\WINDOWS\system32\dllcache\iesetup.dll
- 2006-10-17 19:57:58 36,352 -c—-w C:\WINDOWS\system32\dllcache\imgutil.dll
+ 2007-08-13 22:36:06 36,352 -c–a-w C:\WINDOWS\system32\dllcache\imgutil.dll
- 2006-11-07 11:26:24 92,672 -c–a-w C:\WINDOWS\system32\dllcache\inseng.dll
+ 2007-08-13 22:39:02 92,672 -c–a-w C:\WINDOWS\system32\dllcache\inseng.dll
- 2006-10-17 20:05:10 40,960 -c—-w C:\WINDOWS\system32\dllcache\licmgr10.dll
+ 2007-08-13 22:44:18 40,960 -c–a-w C:\WINDOWS\system32\dllcache\licmgr10.dll
- 2006-10-17 19:56:10 45,568 -c—-w C:\WINDOWS\system32\dllcache\mshta.exe
+ 2007-08-13 22:32:30 45,568 -c–a-w C:\WINDOWS\system32\dllcache\mshta.exe
- 2006-10-17 19:28:56 48,128 -c—-w C:\WINDOWS\system32\dllcache\mshtmler.dll
+ 2007-08-13 22:01:12 48,128 -c–a-w C:\WINDOWS\system32\dllcache\mshtmler.dll
- 2006-11-08 05:03:36 156,160 -c–a-w C:\WINDOWS\system32\dllcache\msls31.dll
+ 2007-08-13 22:54:10 156,160 -c–a-w C:\WINDOWS\system32\dllcache\msls31.dll
+ 2006-09-23 17:12:50 1,497,088 -c—-w C:\WINDOWS\system32\dllcache\shdocvw.dll
+ 2006-09-23 17:12:50 474,112 -c—-w C:\WINDOWS\system32\dllcache\shlwapi.dll
- 2006-11-08 05:03:36 191,488 —-a-w C:\WINDOWS\system32\iepeers.dll
+ 2007-08-13 22:54:10 191,488 —-a-w C:\WINDOWS\system32\iepeers.dll
- 2006-11-07 11:26:42 55,296 —-a-w C:\WINDOWS\system32\iesetup.dll
+ 2007-08-13 22:39:12 55,296 —-a-w C:\WINDOWS\system32\iesetup.dll
- 2006-11-08 05:03:36 180,736 ——w C:\WINDOWS\system32\ieui.dll
+ 2007-08-13 22:54:10 180,736 —-a-w C:\WINDOWS\system32\ieui.dll
- 2006-10-17 19:57:58 36,352 —-a-w C:\WINDOWS\system32\imgutil.dll
+ 2007-08-13 22:36:06 36,352 —-a-w C:\WINDOWS\system32\imgutil.dll
- 2006-11-07 11:26:24 92,672 —-a-w C:\WINDOWS\system32\inseng.dll
+ 2007-08-13 22:39:02 92,672 —-a-w C:\WINDOWS\system32\inseng.dll
- 2006-10-17 20:05:10 40,960 —-a-w C:\WINDOWS\system32\licmgr10.dll
+ 2007-08-13 22:44:18 40,960 —-a-w C:\WINDOWS\system32\licmgr10.dll
- 2003-06-19 01:31:48 17,920 —-a-w C:\WINDOWS\system32\mdimon.dll
+ 2003-06-18 21:31:48 17,920 —-a-w C:\WINDOWS\system32\mdimon.dll
- 2006-10-17 19:58:32 12,288 ——w C:\WINDOWS\system32\msfeedssync.exe
+ 2007-08-13 22:36:40 12,288 —-a-w C:\WINDOWS\system32\msfeedssync.exe
- 2006-10-17 19:56:10 45,568 —-a-w C:\WINDOWS\system32\mshta.exe
+ 2007-08-13 22:32:30 45,568 —-a-w C:\WINDOWS\system32\mshta.exe
- 2006-10-17 19:28:56 48,128 —-a-w C:\WINDOWS\system32\mshtmler.dll
+ 2007-08-13 22:01:12 48,128 —-a-w C:\WINDOWS\system32\mshtmler.dll
- 2006-11-08 05:03:36 156,160 —-a-w C:\WINDOWS\system32\msls31.dll
+ 2007-08-13 22:54:10 156,160 —-a-w C:\WINDOWS\system32\msls31.dll
- 2007-11-30 11:18:51 17,272 ——w C:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 12:39:22 17,272 ——w C:\WINDOWS\system32\spmsg.dll
- 2003-06-19 01:31:44 758,784 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdigraph.dll
+ 2003-06-18 21:31:44 758,784 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdigraph.dll
- 2003-06-19 01:31:46 35,328 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdiui.dll
+ 2003-06-18 21:31:46 35,328 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdiui.dll
- 2003-06-19 01:31:44 758,784 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdigraph.dll
+ 2003-06-18 21:31:44 758,784 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdigraph.dll
- 2003-06-19 01:31:46 35,328 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdiui.dll
+ 2003-06-18 21:31:46 35,328 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdiui.dll
- 2003-06-19 01:31:48 18,944 —-a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
+ 2003-06-18 21:31:48 18,944 —-a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
- 2006-10-17 20:05:58 206,336 ——w C:\WINDOWS\system32\WinFXDocObj.exe
+ 2007-08-13 22:45:16 206,336 —-a-w C:\WINDOWS\system32\WinFXDocObj.exe
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"Washer"="C:\Program Files\Washer\washer.exe" [2003-01-13 818688]
"ccleaner"="C:\Program Files\CCleaner\CCleaner.exe" [2008-04-23 1189104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-03-09 7561216]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-03-09 86016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"KONICA MINOLTA magicolor 2400W STD"="C:\WINDOWS\system32\MSTMON_S.EXE" [2005-06-22 184320]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 282624]
"SecurDisc"="C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-10-26 292152]
"VerizonServicepoint.exe"="C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" [2007-05-11 2061816]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-08-03 36352]
"nwiz"="nwiz.exe" [2006-03-09 C:\WINDOWS\system32\nwiz.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-18 124400]
WordWeb.lnk - C:\Program Files\WordWeb\wweb32.exe [2008-10-27 44384]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSVIDEO5"= concord.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=

R2 MLPTDR_Q;MLPTDR_Q;C:\WINDOWS\system32\MLPTDR_Q.sys [2003-07-22 18848]
S2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
S2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [ ]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{049cb996-a465-11db-a634-00e04cb779fd}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2008-10-27 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe []
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-30 15:27:34
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\isro5pa4.default\Cache\02B5AE61d01 29103 bytes
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\isro5pa4.default\Cache\041FDDA1d01 21267 bytes
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\isro5pa4.default\Cache\049EDDB9d01 18154 bytes
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\isro5pa4.default\Cache\05647BF2d01 37265 bytes
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\isro5pa4.default\Cache\0773DC05d01 17591 bytes
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\isro5pa4.default\Cache\07E2DDB6d01 23056 bytes
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\isro5pa4.default\Cache\0838D9CBd01 66563 bytes
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\isro5pa4.default\Cache\0A983464d01 173696 bytes
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\isro5pa4.default\Cache\0C14EED4d01 20773 bytes
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\isro5pa4.default\Cache\0CCB0097d01
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\isro5pa4.default\Cache\0D26A8DFd01 23004 bytes
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\isro5pa4.default\Cache\0D8BA351d01 50040 bytes
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\isro5pa4.default\Cache\10EA7ECAd01
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\#SharedObjects
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\#SharedObjects\DV57Q7BN
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\#SharedObjects\DV57Q7BN\www.pornhost.com
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\#SharedObjects\DV57Q7BN\www.pornhost.com\com.jeroenwijering.players.sol 66 bytes
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\#SharedObjects\DV57Q7BN\www.yourfilehost.com
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\#SharedObjects\DV57Q7BN\www.yourfilehost.com\flash
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\#SharedObjects\DV57Q7BN\www.yourfilehost.com\flash\flvplayer7.swf
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\#SharedObjects\DV57Q7BN\www.yourfilehost.com\flash\flvplayer7.swf\UserVolume.sol 55 bytes
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\macromedia.com
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\macromedia.com\support
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.pornhost.com
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.pornhost.com\settings.sol 86 bytes
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.yourfilehost.com
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.yourfilehost.com\settings.sol 90 bytes
C:\Documents and Settings\Admin\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol 463 bytes

scan completed successfully
hidden files: 30

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDSSserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSmqlt.sys"
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
.
**************************************************************************
.
Completion time: 2008-10-30 15:31:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-30 19:31:16
ComboFix2.txt 2008-10-28 02:34:50
ComboFix3.txt 2008-10-28 01:39:32
ComboFix4.txt 2008-10-27 23:30:08
ComboFix5.txt 2008-10-30 19:19:33

Pre-Run: 15,904,251,904 bytes free
Post-Run: 15,956,512,768 bytes free

281 — E O F — 2008-10-28 14:18:49

=======================================================
=======================================================

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:56:07 PM, on 10/30/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\MSTMON_S.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Washer\washer.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\WordWeb\wweb32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/rlidOfficeUpdate?clid=1033
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [KONICA MINOLTA magicolor 2400W STD] C:\WINDOWS\system32\MSTMON_S.EXE STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Washer] C:\Program Files\Washer\washer.exe /0
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O8 - Extra context menu item: &Yahoo;! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS; - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1143246383000
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143472817734
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (file missing)
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

–
End of file - 8442 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI