Hi Essexboy, sorry for delayed my report. Therefore I really appriciate for your assistance. .
Step 1: I run Process (in Icesword), there was no process in red color.
Step 2: I clicked the "Win32 Services" tab. There was no red colored service entry.
Step 3: finally I clicked the "SSDT" tab. There was no red colored entry.
Also I am posting my ComboFix log report. It is given below: ( By the way after the first scan by combofix on 17 january, no virus warning appeared again. Before it happened that it used to warn a virus "Trojan" malware by avast)
HERE IS THE COMBOFIX LOG REPORT:
ComboFix 08-01-17.5 - muugii 2008-01-20 13:32:23.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.248 [GMT -8:00]
Running from: C:\Documents and Settings\muugii\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\muugii\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE
C:\WINDOWS\system32\drivers\Ejs75.sys
F:\SVCH0ST.EXE
.
((((((((((((((((((((((((( Files Created from 2007-12-20 to 2008-01-20 )))))))))))))))))))))))))))))))
.
2008-01-20 02:03 . 2008-01-20 02:03 <DIR> d-------- C:\Program Files\Windows Live Favorites
2008-01-19 12:03 . 2008-01-19 12:03 <DIR> d-------- C:\Program Files\VideoLAN
2008-01-19 09:37 . 2008-01-19 09:37 <DIR> d-------- C:\Program Files\uTorrent
2008-01-19 09:37 . 2008-01-20 13:34 <DIR> d-------- C:\Documents and Settings\muugii\Application Data\uTorrent
2008-01-19 03:06 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-01-19 03:06 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-01-19 03:06 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-01-18 11:28 . 2003-12-04 11:19 974,848 --a------ C:\WINDOWS\system32\mfc70.dll
2008-01-18 11:28 . 2003-12-04 11:19 487,424 --a------ C:\WINDOWS\system32\msvcp70.dll
2008-01-18 11:28 . 2003-12-04 11:19 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-01-18 08:34 . 2008-01-18 08:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Macrovision
2008-01-18 01:56 . 2008-01-18 01:56 <DIR> d-------- C:\Program Files\Common Files\Macromedia Shared
2008-01-18 01:52 . 2008-01-18 11:28 <DIR> d-------- C:\Program Files\Common Files\Macromedia
2008-01-18 01:49 . 2008-01-18 11:28 <DIR> d-------- C:\Program Files\Macromedia
2008-01-18 01:05 . 2008-01-20 02:03 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2008-01-18 01:05 . 2008-01-18 01:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2008-01-18 00:18 . 2007-10-10 15:55 6,065,664 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-18 00:18 . 2007-06-30 19:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-18 00:18 . 2007-06-30 19:36 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-18 00:18 . 2007-10-10 15:55 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-18 00:18 . 2007-10-10 15:55 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-18 00:18 . 2007-10-10 15:55 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-18 00:18 . 2007-10-10 15:55 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-18 00:18 . 2007-10-10 15:55 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-18 00:18 . 2007-10-10 02:59 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-17 13:01 . 2004-08-03 20:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-01-17 03:00 . 2008-01-19 03:14 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-01-17 03:00 . 2006-09-06 17:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-01-17 00:59 . 2008-01-17 00:59 <DIR> d-------- C:\Documents and Settings\muugii\Application Data\Yahoo!
2008-01-17 00:59 . 2008-01-17 00:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-01-17 00:53 . 2008-01-17 00:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-01-17 00:51 . 2008-01-17 00:53 <DIR> d-------- C:\Program Files\Yahoo!
2008-01-10 04:03 . 2008-01-08 04:13 202,160 --a------ C:\WINDOWS\system32\idmmbc.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 21:29 --------- d-----w C:\Documents and Settings\muugii\Application Data\DMCache
2008-01-18 19:28 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-18 16:42 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-18 09:49 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-17 12:27 --------- d-----w C:\Program Files\Internet Download Manager
2008-01-17 08:38 --------- d-----w C:\Documents and Settings\muugii\Application Data\IDM
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-28 01:39 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
2004-03-28 16:16 744,529 ----a-w C:\Program Files\bazookasetup.exe
2004-03-28 11:36 571,392 ----a-w C:\Program Files\SoftyVisII.exe
2004-03-28 11:26 197,120 ----a-w C:\Program Files\picturevizII.exe
2004-03-27 16:47 4,189,850 ----a-w C:\Program Files\sysclean.zip
.
((((((((((((((((((((((((((((( snapshot_2008-01-19_ 4.27.25.10 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-18 07:53:58 225,280 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-20 21:32:07 225,280 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-18 07:53:58 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-20 21:32:07 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-18 07:53:58 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-20 21:32:07 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-18 07:53:58 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-20 21:32:07 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-18 07:53:58 1,777,664 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-20 21:32:07 2,453,504 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
- 2008-01-18 07:53:58 208,896 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-20 21:32:07 278,528 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
+ 2007-08-14 02:54:10 765,952 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
- 2007-08-14 02:54:10 765,952 -c--a-w C:\WINDOWS\system32\dllcache\VGX.dll
+ 2007-07-12 23:31:54 765,952 -c--a-w C:\WINDOWS\system32\dllcache\vgx.dll
+ 2008-01-20 15:43:12 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_450.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-01-10 04:29 2577840]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-12-17 17:13 3810544]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 20:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-03-28 02:12 77824]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-03-28 03:11 185896]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ejs75.sys]
@="Driver"
R3 cwrwdm;SoundFusion WDM Driver;C:\WINDOWS\system32\DRIVERS\cwrwdm.sys [2004-08-03 14:32]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-20 21:26:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-20 12:46:10 C:\WINDOWS\Tasks\User_Feed_Synchronization-{B87E9C15-03AF-4F7A-868B-D59DF316F98B}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-20 13:34:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-20 13:34:53
ComboFix-quarantined-files.txt 2008-01-20 21:34:50
ComboFix2.txt 2008-01-19 14:39:41
ComboFix3.txt 2008-01-19 12:27:47
ComboFix4.txt 2008-01-18 07:59:21
ComboFix5.txt 2008-01-18 07:28:04
.
2008-01-20 10:03:56 --- E O F ---