Thanks for your reply Greyknight17.
I performed a scan with Malwarebytes ' Anti-Malware. I had some partial success. My hard drive is partitioned into a C drive and a F drive (which contains my active Windows XP installation). Scanning C drive completed successfully and detected a number of threats which were subsequently deleted. One of the threats detected was the Vundo/Winfixer trojan. Everytime I tried to scan the F drive (even in safe mode) the program freezed on me. It often freezed while scanning the Windows folder or the Local Settings folder.
Here' the Malwarebytes ' Anti-Malware log for the scan on C (which is the only scan which would complete):Malwarebytes' Anti-Malware 1.11
Database version: 669
Scan type: Full Scan (C:\|)
Objects scanned: 67072
Time elapsed: 33 minute(s), 5 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 12
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 8
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
F:\WINDOWS\system32\rvwxdyot.dll (Trojan.Vundo) -> No action taken.
F:\WINDOWS\system32\urqNeeDW.dll (Trojan.Vundo) -> No action taken.
F:\WINDOWS\system32\__c0059A9C.dat (Trojan.Agent) -> No action taken.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0d7f67b2-ac46-46ab-8e50-c707ee3de0f0} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{0d7f67b2-ac46-46ab-8e50-c707ee3de0f0} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0059a9c (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\aldd (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BMcb8f2231 (Trojan.Agent) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: f:\windows\system32\urqneedw -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: f:\windows\system32\urqneedw -> No action taken.
Folders Infected:
(No malicious items detected)
Files Infected:
F:\WINDOWS\system32\rvwxdyot.dll (Trojan.Vundo) -> No action taken.
F:\WINDOWS\system32\toydxwvr.ini (Trojan.Vundo) -> No action taken.
F:\WINDOWS\system32\urqNeeDW.dll (Trojan.Vundo) -> No action taken.
F:\WINDOWS\system32\WDeeNqru.ini (Trojan.Vundo) -> No action taken.
F:\WINDOWS\system32\WDeeNqru.ini2 (Trojan.Vundo) -> No action taken.
F:\WINDOWS\system32\ntkkgxuo.dll (Trojan.Agent) -> No action taken.
F:\WINDOWS\system32\__c0059A9C.dat (Trojan.Agent) -> No action taken.
F:\WINDOWS\system32\__c00772E9.dat (Trojan.Agent) -> No action taken.
--------------------------------------
Some of the infected files could only be deleted on restart. I restarted and ran the scan on C again. It detected 4 infected files which I subsequently deleted. Here is the log:Malwarebytes' Anti-Malware 1.11
Database version: 669
Scan type: Full Scan (C:\|)
Objects scanned: 67233
Time elapsed: 31 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
F:\WINDOWS\system32\rvwxdyot.dll (Trojan.Vundo) -> No action taken.
F:\WINDOWS\system32\toydxwvr.ini (Trojan.Vundo) -> No action taken.
F:\WINDOWS\system32\urqNeeDW.dll (Trojan.Vundo) -> No action taken.
F:\WINDOWS\system32\WDeeNqru.ini (Trojan.Vundo) -> No action taken.
-------------------------------------------------
After restarting and scanning again Malewarebytes' Anti-Malware did not find any problems. I then launched ComboFix. Here's the log:ComboFix 08-04-20.5 - Pablo 2008-04-23 15:07:05.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.546 [GMT 9.5:30]
Running from: F:\Documents and Settings\Pablo\My Documents\ComboFix.exe
Command switches used :: F:\Documents and Settings\Pablo\My Documents\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
F:\WINDOWS\pskt.ini
F:\WINDOWS\rs.txt
F:\WINDOWS\system32\ameyrhpp.dll
F:\WINDOWS\system32\fccyvSKa.dll
F:\WINDOWS\system32\mcrh.tmp
F:\WINDOWS\system32\ntduiqss.dll
F:\WINDOWS\system32\ntkkgxuo.dll
F:\WINDOWS\system32\oryakqen.dll
F:\WINDOWS\system32\vcqkqsen.dll
F:\WINDOWS\system32\xsiotcct.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-23 to 2008-04-23 )))))))))))))))))))))))))))))))
.
2008-04-23 14:48 . 2008-04-23 12:01 212,992 --a------ F:\WINDOWS\wdpoefan.dll
2008-04-23 14:48 . 2008-04-23 12:01 212,992 --a------ F:\WINDOWS\qnmargolwdn.dll
2008-04-23 14:48 . 2008-04-23 12:01 167,936 --a------ F:\WINDOWS\vadokmxt.dll
2008-04-23 14:48 . 2008-04-23 12:01 151,552 --a------ F:\WINDOWS\dpevflbg.dll
2008-04-23 14:48 . 2008-04-23 12:01 94,208 --a------ F:\WINDOWS\olgdqarf.exe
2008-04-23 14:48 . 2008-04-23 12:01 81,920 --a------ F:\WINDOWS\wxvgsdbq.exe
2008-04-22 19:39 . 2008-04-22 19:39 <DIR> d-------- F:\Program Files\Malwarebytes' Anti-Malware
2008-04-22 19:39 . 2008-04-22 19:39 <DIR> d-------- F:\Documents and Settings\Pablo\Application Data\Malwarebytes
2008-04-22 19:39 . 2008-04-22 19:39 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-21 19:14 . 2008-04-22 18:46 878 ---hs---- F:\WINDOWS\system32\syyyoufw.ini
2008-04-20 15:44 . 2008-04-22 19:12 109,748 --a------ F:\WINDOWS\BMcb8f2231.xml
2008-04-20 15:44 . 2008-04-21 18:58 474 ---hs---- F:\WINDOWS\system32\hhfmcrmu.ini
2008-04-18 22:50 . 2008-04-18 22:50 <DIR> d-------- F:\Program Files\CCleaner
2008-04-18 22:08 . 2008-04-18 22:08 <DIR> d-------- F:\Program Files\VS Revo Group
2008-04-14 23:34 . 2007-11-14 09:02 43,090,956 --a------ F:\nfs.exe
2008-04-14 01:06 . 2004-08-03 23:08 25,600 --a------ F:\WINDOWS\system32\drivers\usbser.sys
2008-04-14 01:06 . 2004-08-03 23:08 25,600 --a--c--- F:\WINDOWS\system32\dllcache\usbser.sys
2008-04-14 01:06 . 2008-04-14 01:06 0 --ah----- F:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-04-14 01:06 . 2008-04-14 01:06 0 --ah----- F:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-04-14 00:57 . 2007-11-29 10:33 1,419,232 --a------ F:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-04-14 00:57 . 2008-02-01 15:17 138,112 --a------ F:\WINDOWS\system32\drivers\nmwcdnsu.sys
2008-04-14 00:57 . 2007-11-29 10:39 95,744 --a------ F:\WINDOWS\system32\nmwcdcocls.dll
2008-04-14 00:57 . 2007-11-29 10:39 19,328 --a------ F:\WINDOWS\system32\drivers\ccdcmbo.sys
2008-04-14 00:57 . 2007-11-29 10:39 16,896 --a------ F:\WINDOWS\system32\drivers\ccdcmb.sys
2008-04-14 00:57 . 2008-02-01 15:17 8,320 --a------ F:\WINDOWS\system32\drivers\nmwcdnsuc.sys
2008-04-14 00:57 . 2007-11-29 10:39 8,064 --a------ F:\WINDOWS\system32\drivers\usbser_lowerfltj.sys
2008-04-14 00:57 . 2007-11-29 10:39 8,064 --a------ F:\WINDOWS\system32\drivers\usbser_lowerflt.sys
2008-04-14 00:56 . 2008-04-14 00:56 <DIR> d-------- F:\Program Files\Common Files\Nokia
2008-04-14 00:53 . 2008-04-14 00:53 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Installations
2008-04-13 17:21 . 2008-04-13 17:21 <DIR> d-------- F:\Documents and Settings\Pablo\Application Data\vlc
2008-04-13 17:20 . 2008-04-13 17:20 <DIR> d-------- F:\Program Files\VideoLAN
2008-04-13 01:48 . 2008-04-13 01:48 <DIR> d-------- F:\Documents and Settings\Pablo\Application Data\Leadertech
2008-04-12 12:28 . 2008-04-12 12:34 <DIR> d-------- F:\Program Files\Incoming
2008-04-12 02:22 . 2008-04-12 03:13 6,918,048 --a------ F:\NVE2D.tmp
2008-04-12 02:22 . 2008-04-12 02:22 2,928 --a------ F:\NVE2C.tmp
2008-04-10 22:27 . 2008-04-10 22:27 <DIR> d-------- F:\Documents and Settings\Pablo\Application Data\THQ
2008-04-10 21:43 . 2008-04-10 21:43 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\InstallShield
2008-04-08 22:33 . 2008-04-08 22:33 <DIR> d-------- F:\Documents and Settings\Pablo\Application Data\NSeries
2008-04-08 22:16 . 2008-04-08 22:23 <DIR> d-------- F:\Documents and Settings\Pablo\Application Data\ROUTE 66 Sync
2008-04-08 19:40 . 2008-04-08 19:45 <DIR> d-------- F:\Program Files\Windows Live
2008-04-08 19:40 . 2008-04-08 19:44 <DIR> d--hsc--- F:\Program Files\Common Files\WindowsLiveInstaller
2008-04-08 19:40 . 2008-04-08 19:40 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-08 00:27 . 2008-04-21 23:47 151,388 --a------ F:\Documents and Settings\Pablo\Application Data\NMM-MetaData.db
2008-04-07 23:59 . 2008-04-07 23:59 <DIR> d-------- F:\Documents and Settings\Pablo\Application Data\AdobeAUM
2008-04-07 23:08 . 2008-04-07 23:08 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Nokia
2008-04-07 23:01 . 2008-04-07 23:01 <DIR> d-------- F:\Program Files\SimpleCenter
2008-04-07 23:01 . 2008-04-07 23:01 <DIR> d-------- F:\Program Files\Common Files\i4j_jres
2008-04-07 23:00 . 2008-04-07 23:11 <DIR> d-------- F:\Documents and Settings\Pablo\Application Data\Nokia
2008-04-07 23:00 . 2008-04-07 23:58 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\PC Suite
2008-04-07 22:59 . 2008-04-07 22:59 <DIR> d-------- F:\Program Files\Common Files\PCSuite
2008-04-07 22:58 . 2008-04-07 22:58 <DIR> d-------- F:\Program Files\PC Connectivity Solution
2008-04-07 22:58 . 2008-04-14 00:57 <DIR> d-------- F:\Program Files\Nokia
2008-04-07 22:58 . 2008-04-07 22:58 <DIR> d-------- F:\Program Files\DIFX
2008-04-07 22:58 . 2008-04-07 23:01 <DIR> d-------- F:\Documents and Settings\Pablo\Application Data\PC Suite
2008-04-07 22:58 . 2008-02-01 15:17 90,624 --a------ F:\WINDOWS\system32\nmwcdcls.dll
2008-04-07 02:58 . 2008-04-07 03:31 4,520,784 --a------ F:\NVE2A.tmp
2008-04-07 01:30 . 2008-04-07 01:55 3,623,232 --a------ F:\NVE27.tmp
2008-04-07 01:30 . 2008-04-07 01:30 2,928 --a------ F:\NVE26.tmp
2008-04-07 01:30 . 2008-04-07 01:30 2,928 --a------ F:\NVE25.tmp
2008-04-04 04:00 . 2008-04-04 04:42 6,157,152 --a------ F:\NVE10.tmp
2008-04-04 02:02 . 2008-04-04 04:00 5,249,664 --a------ F:\NVEC.tmp
2008-04-04 02:02 . 2008-04-04 02:02 2,928 --a------ F:\NVEB.tmp
2008-04-04 02:02 . 2008-04-04 02:02 2,928 --a------ F:\NVEA.tmp
2008-04-02 01:21 . 2008-04-02 02:16 7,293,936 --a------ F:\NVE3E.tmp
2008-04-02 01:21 . 2008-04-02 01:21 2,928 --a------ F:\NVE3D.tmp
2008-04-02 01:20 . 2008-04-02 01:20 <DIR> d-------- F:\Documents and Settings\Pablo\Application Data\DivX
2008-04-01 01:33 . 2008-04-01 01:33 <DIR> d-------- F:\Program Files\Trend Micro
2008-03-29 02:42 . 2008-03-29 04:23 4,166,448 --a------ F:\NVE22.tmp
2008-03-29 01:03 . 2008-03-29 02:42 4,092,672 --a------ F:\NVE1E.tmp
2008-03-29 01:03 . 2008-03-29 01:03 2,928 --a------ F:\NVE1D.tmp
2008-03-29 01:03 . 2008-03-29 01:03 2,928 --a------ F:\NVE1C.tmp
2008-03-28 22:21 . 2008-03-28 22:25 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-03-23 20:20 . 2008-03-23 20:22 <DIR> d-------- F:\Program Files\Spyware Terminator
2008-03-23 20:20 . 2008-03-24 11:52 <DIR> d-------- F:\Documents and Settings\Pablo\Application Data\Spyware Terminator
2008-03-23 20:20 . 2008-03-23 20:20 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-03-23 20:20 . 2008-03-23 20:20 138,752 --a------ F:\WINDOWS\system32\drivers\sp_rsdrv2.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-23 05:40 --------- d-----w F:\Program Files\Common Files\Symantec Shared
2008-04-21 15:00 --------- d-----w F:\Program Files\Incomplete
2008-04-21 13:58 --------- d-----w F:\Program Files\LimeWire
2008-04-21 12:03 --------- d-----w F:\Documents and Settings\Pablo\Application Data\LimeWire
2008-04-20 08:34 22,328 ----a-w F:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-20 08:34 103,736 ----a-w F:\WINDOWS\system32\PnkBstrB.exe
2008-04-20 07:36 --------- d-----w F:\Documents and Settings\Pablo\Application Data\Azureus
2008-04-17 14:41 --------- d-----w F:\Program Files\Azureus
2008-04-16 13:14 --------- d-----w F:\Program Files\Spybot - Search & Destroy
2008-04-16 13:14 --------- d-----w F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-16 12:18 66,872 ----a-w F:\WINDOWS\system32\PnkBstrA.exe
2008-04-12 08:32 --------- d-----w F:\Program Files\Electronic Arts
2008-04-12 04:19 --------- d--h--w F:\Program Files\InstallShield Installation Information
2008-04-11 11:06 --------- d-----w F:\Program Files\Common Files\Adobe
2008-04-10 11:53 --------- d-----w F:\Program Files\THQ
2008-04-10 11:53 --------- d-----w F:\Program Files\Common Files\InstallShield
2008-04-07 14:43 --------- d-----w F:\Documents and Settings\Pablo\Application Data\AdobeUM
2008-03-30 12:51 --------- d-----w F:\Documents and Settings\Pablo\Application Data\Hamachi
2008-03-24 22:44 --------- d-----w F:\Documents and Settings\All Users\Application Data\Symantec
2008-03-24 04:43 --------- d-----w F:\Program Files\Ubisoft
2008-03-23 10:10 --------- d-----w F:\Program Files\Webteh
2008-03-23 10:10 --------- d-----w F:\Documents and Settings\Pablo\Application Data\BSplayer
2008-03-21 13:30 --------- d-----w F:\Program Files\ASUS
2008-03-13 09:20 --------- d-----w F:\Program Files\Sierra Online
2008-03-13 05:38 --------- d-----w F:\Documents and Settings\Pablo\Application Data\uTorrent
2008-03-06 11:02 706 ----a-w F:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-06 11:02 23,904 ----a-w F:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-06 11:02 10,537 ----a-w F:\WINDOWS\system32\drivers\COH_Mon.cat
2008-03-05 15:16 --------- d-----w F:\Program Files\eMule
2008-02-24 06:44 691,545 ----a-w F:\WINDOWS\unins000.exe
2008-02-02 12:48 87,608 ----a-w F:\Documents and Settings\Pablo\Application Data\inst.exe
2008-02-02 12:48 47,360 ----a-w F:\Documents and Settings\Pablo\Application Data\pcouffin.sys
2007-12-13 03:40 6,177,423,528 ----a-w F:\Program Files\Need for speed Prostreet Iso.nrg
2007-11-21 12:51 22,328 ----a-w F:\Documents and Settings\Pablo\Application Data\PnkBstrK.sys
.
<pre>
----a-w 17,529,400 2007-10-04 17:06:45 F:\Documents and Settings\Pablo\My Documents\Downloads\Sony Image Converter 2 .exe
</pre>
------- Sigcheck -------
2007-12-04 22:36 360576 e7dfcffa380749b8626ad71e8f367dcb F:\WINDOWS\system32\dllcache\TCPIP.SYS
2007-12-04 22:36 360576 e7dfcffa380749b8626ad71e8f367dcb F:\WINDOWS\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D1DE7404-BFDF-430B-AB48-3EBF39F05C9F}]
2008-04-23 12:01 212992 --a------ F:\WINDOWS\qnmargolwdn.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{547D68A0-5DA7-46A9-AF9A-AF8E80321F8C}"= "F:\WINDOWS\dpevflbg.dll" [2008-04-23 12:01 151552]
[HKEY_CLASSES_ROOT\clsid\{547d68a0-5da7-46a9-af9a-af8e80321f8c}]
[HKEY_CLASSES_ROOT\dpevflbg.1]
[HKEY_CLASSES_ROOT\TypeLib\{6B07F9E4-138B-45C2-9A82-8651EEC5765B}]
[HKEY_CLASSES_ROOT\dpevflbg]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
"MsnMsgr"="F:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"ctfmon.exe"="F:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:26 15360]
"DAEMON Tools Lite"="F:\Program Files\DAEMON Tools Lite\daemon.exe" [2007-12-29 21:35 486856]
"MySpaceIM"="F:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-19 11:17 8720384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="F:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" [2004-11-09 10:38 532480]
"NVRTCLK"="F:\WINDOWS\system32\NVRTCLK\NVRTClk.exe" [2003-12-30 19:14 24576]
"NvCplDaemon"="F:\WINDOWS\system32\NvCpl.dll" [2007-09-17 01:07 8491008]
"nwiz"="nwiz.exe" [2007-09-17 01:07 1626112 F:\WINDOWS\system32\nwiz.exe]
"DownloadAccelerator"="F:\Program Files\DAP\DAP.exe" [2006-08-03 16:42 2864276]
"NeroFilterCheck"="F:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 19:50 77824 F:\WINDOWS\SOUNDMAN.EXE]
"PWRISOVM.EXE"="F:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-07 09:35 200704]
"ccApp"="F:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-09-03 03:04 84640]
"osCheck"="F:\Program Files\Norton AntiVirus\osCheck.exe" [2006-09-05 21:22 26248]
"NvMediaCenter"="F:\WINDOWS\system32\NvMcTray.dll" [2007-09-17 01:07 81920]
"SunJavaUpdateSched"="F:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"Symantec PIF AlertEng"="F:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 18:51 583048]
"AsusStartupHelp"="F:\Program Files\ASUS\AASP\1.00.14\AsRunHelp.exe" [2006-11-14 13:25 363008]
"NSLauncher"="F:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2007-10-01 19:59 3104768]
"Adobe Photo Downloader"="F:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]
"f00473b8"="F:\WINDOWS\system32\rvwxdyot.dll" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="F:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 08:26 15360]
"MySpaceIM"="F:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-19 11:17 8720384]
F:\Documents and Settings\Pablo\Start Menu\Programs\Startup\
MagicDisc.lnk - F:\Program Files\MagicDisc\MagicDisc.exe [2007-09-08 21:32:23 557568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"wdpoefan"= {88D064D1-CF7D-48DE-B97E-B43952A1B06C} - F:\WINDOWS\wdpoefan.dll [2008-04-23 12:01 212992]
"vadokmxt"= {4A3E20C0-18A1-4097-8A15-0094056084CB} - F:\WINDOWS\vadokmxt.dll [2008-04-23 12:01 167936]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xsiotcct]
xsiotcct.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.ac3acm"= ac3acm.acm
"msacm.lameacm"= lameACM.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2006-10-09 11:28 139264 F:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2007-12-19 11:17 8720384 F:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"F:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"F:\\Program Files\\eMule\\eMule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"F:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"F:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"F:\\Program Files\\DAP\\DAP.exe"=
"F:\\Program Files\\uTorrent\\uTorrent.exe"=
"F:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"F:\\Program Files\\LimeWire\\LimeWire.exe"=
"F:\\Program Files\\Azureus\\Azureus.exe"=
"F:\\WINDOWS\\system32\\PnkBstrA.exe"=
"F:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Sierra Entertainment\\Empire Earth III\\EE3.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"F:\\Program Files\\Teamspeak2_RC2 Server\\server_windows.exe"=
"C:\\Program Files\\CoH Opposing Fronts\\RelicCOH.exe"=
"F:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"F:\\Program Files\\Sierra Online\\Red Baron Arcade\\Red Baron Arcade.exe"=
"F:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"F:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"F:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"F:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"F:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"F:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
R3 ngrpci;NETGEAR FA310TX Fast Ethernet Adapter Driver;F:\WINDOWS\system32\DRIVERS\ngrpci.sys [2001-08-17 12:12]
S3 FileObjInfo;STFileDriver;F:\Documents and Settings\All Users\Application Data\Spyware Terminator\FileObjInfo.sys [2008-03-23 20:20]
S3 k600bus;Sony Ericsson 600i driver (WDM);F:\WINDOWS\system32\DRIVERS\k600bus.sys [2005-05-11 20:42]
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;F:\WINDOWS\system32\DRIVERS\k600mdfl.sys [2005-05-11 20:42]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;F:\WINDOWS\system32\DRIVERS\k600mdm.sys [2005-05-11 20:42]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;F:\WINDOWS\system32\DRIVERS\k600mgmt.sys [2005-05-11 20:42]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;F:\WINDOWS\system32\DRIVERS\k600obex.sys [2005-05-11 20:42]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;F:\WINDOWS\system32\drivers\nmwcdnsu.sys [2008-02-01 15:17]
S3 nmwcdnsuc;Nokia USB Flashing Generic;F:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2008-02-01 15:17]
S3 PCASp50;PCASp50 NDIS Protocol Driver;F:\WINDOWS\system32\Drivers\PCASp50.sys []
S3 upperdev;upperdev;F:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2007-11-29 10:39]
S3 UsbserFilt;UsbserFilt;F:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2007-11-29 10:39]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-18 10:30:11 F:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Pablo.job"
- F:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-23 15:11:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: F:\WINDOWS\explorer.exe
-> F:\WINDOWS\system32\nview.dll
.
------------------------ Other Running Processes ------------------------
.
F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
F:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
F:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
F:\WINDOWS\system32\nvsvc32.exe
F:\WINDOWS\system32\PnkBstrA.exe
F:\WINDOWS\system32\rundll32.exe
F:\Program Files\Spyware Terminator\sp_rsser.exe
F:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
F:\WINDOWS\system32\rundll32.exe
F:\Program Files\PC Connectivity Solution\ServiceLayer.exe
F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
F:\Program Files\Windows Live\Messenger\usnsvc.exe
F:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
F:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
F:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
F:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
F:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
.
**************************************************************************
.
Completion time: 2008-04-23 15:17:11 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-23 05:47:01
Pre-Run: 3,853,774,848 bytes free
Post-Run: 5,968,527,360 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
297 --- E O F --- 2007-08-23 10:21:46
-------------------------------------------------------------------------
After this, I attempted to run VundoFix (from http://www.softpedia.../VundoFix.shtml and http://www.majorgeek...nload4954.html) but scans with VundoFix froze my computer everytime mid-scan. I also tried two full-system scans with Norton-Antivirus 2007. Both scans caused my computer to shut down and restart automatically mid-scan. An anti-spyware scan with Lavasoft Ad-aware also still freezes mid-scan. There's still something nasty in there!