Iv'e read through some of the other post concerning this trojandownloader.xs. There seems to be a slight;y different route taken by each person. I did the combo fix and saved the log. I'm posting it here. I dont have this HijackThis program, but I purchased the newest version of Spyhunter and I have the free version of the Lavasoft program: Ad-Aware. Neighter of which has habdled the problem. I also have Norton 2008. Thanks for the help.
ComboFix 08-03-09.1 - joxaal 2008-03-09 14:27:34.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.532 [GMT -5:00]
Running from: C:\Documents and Settings\joxaal\Local Settings\Temporary Internet Files\Content.IE5\IR8JUP2L\ComboFix[1].exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\joxaal\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\joxaal\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\joxaal\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Program Files\Common Files\Yazzle1552OinAdmin.exe
C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
C:\Program Files\ISM
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\QdrDrive12.dll
C:\Program Files\QdrDrive\qdrloader.exe
C:\Program Files\QdrModule
C:\Program Files\QdrModule\QdrModule13.exe
C:\Program Files\seekmo
C:\Program Files\seekmo\seekmohook.dll
C:\WINDOWS\180ax.exe
C:\WINDOWS\2020search.dll
C:\WINDOWS\2020search2.dll
C:\WINDOWS\bjam.dll
C:\WINDOWS\bokja.exe
C:\WINDOWS\cdsm32.dll
C:\WINDOWS\default.htm
C:\WINDOWS\mspphe.dll
C:\WINDOWS\mssvr.exe
C:\WINDOWS\saiemod.dll
C:\WINDOWS\salm.exe
C:\WINDOWS\stcloader.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\system32\khffdec.dll
C:\WINDOWS\system32\msixu.dll
C:\WINDOWS\system32\wer8274.dll
C:\WINDOWS\TEMP\salm.exe
C:\WINDOWS\updatetc.exe
C:\WINDOWS\voiceip.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-09 to 2008-03-09 )))))))))))))))))))))))))))))))
.
2008-03-09 13:50 . 2008-03-09 13:50 <DIR> d-------- C:\Program Files\zango
2008-03-09 13:18 . 2008-03-09 13:18 19,200 --a------ C:\WINDOWS\didduid.ini
2008-03-09 12:46 . 2008-03-09 12:46 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-03-09 12:46 . 2008-03-09 13:18 <DIR> d-------- C:\Program Files\180solutions
2008-03-09 12:46 . 2008-03-09 13:18 <DIR> d-------- C:\Program Files\180searchassistant
2008-03-09 12:46 . 2008-03-09 13:50 <DIR> d-------- C:\Program Files\180search assistant
2008-03-09 02:26 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\SYSTEM32\VCCLSID.exe
2008-03-09 02:26 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\SYSTEM32\SrchSTS.exe
2008-03-09 02:26 . 2008-03-09 02:15 86,528 --a------ C:\WINDOWS\SYSTEM32\VACFix.exe
2008-03-09 02:26 . 2008-03-05 23:29 82,432 --a------ C:\WINDOWS\SYSTEM32\IEDFix.exe
2008-03-09 02:26 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\SYSTEM32\Process.exe
2008-03-09 02:26 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\SYSTEM32\dumphive.exe
2008-03-09 02:26 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\SYSTEM32\WS2Fix.exe
2008-03-08 23:50 . 2008-03-08 23:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-08 23:18 . 2008-03-08 23:18 <DIR> d--h----- C:\WINDOWS\SYSTEM32\GroupPolicy
2008-03-08 21:08 . 2008-03-08 21:08 <DIR> d-------- C:\WINDOWS\FLEOK
2008-03-08 21:08 . 2008-03-08 21:08 <DIR> d-------- C:\Program Files\stc
2008-03-08 21:08 . 2008-03-08 21:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-08 21:08 . 2008-03-08 21:08 32,000 --a------ C:\WINDOWS\msapasrc.dll
2008-03-08 21:08 . 2008-03-08 21:08 29,440 --a------ C:\WINDOWS\SYSTEM32\SIPSPI32.dll
2008-03-08 21:08 . 2008-03-08 21:08 29,184 --a------ C:\WINDOWS\ntnut.exe
2008-03-08 21:08 . 2008-03-08 21:08 28,672 --a------ C:\WINDOWS\123messenger.per
2008-03-08 21:08 . 2008-03-08 21:08 27,904 --a------ C:\WINDOWS\shdocpl.dll
2008-03-08 21:08 . 2008-03-08 21:08 26,368 --a------ C:\WINDOWS\msa64chk.dll
2008-03-08 21:08 . 2008-03-08 21:08 11,520 --a------ C:\WINDOWS\SYSTEM32\ntnut32.exe
2008-03-08 21:08 . 2008-03-08 21:08 8,448 --a------ C:\WINDOWS\SYSTEM32\shdocpe.dll
2008-03-08 21:08 . 2008-03-08 21:08 8,448 --a------ C:\WINDOWS\SYSTEM32\MSNSA32.dll
2008-03-08 21:07 . 2008-03-08 21:07 <DIR> d-------- C:\Program Files\Sysmnt
2008-03-08 20:52 . 2008-03-08 20:52 295,819 --a------ C:\WINDOWS\SYSTEM32\L6555.tmp
2008-03-08 20:52 . 2008-03-08 20:52 229,532 --a------ C:\WINDOWS\SYSTEM32\L53FF.tmp
2008-03-08 20:52 . 2008-03-08 20:52 88,587 --a------ C:\WINDOWS\SYSTEM32\mgmrwmrv.exe
2008-03-08 20:52 . 2008-03-08 20:52 4 --a------ C:\WINDOWS\SYSTEM32\winfrun32.bin
2008-03-08 15:31 . 2008-01-12 19:32 23,904 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.sys
2008-03-08 15:31 . 2008-01-15 10:54 10,537 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.cat
2008-03-08 15:31 . 2008-01-15 06:28 706 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\COH_Mon.inf
2008-02-25 19:08 . 2007-01-31 10:58 266,240 --------- C:\WINDOWS\SBCDSL.exe
2008-02-25 19:08 . 2007-01-31 10:58 6,345 -ra------ C:\WINDOWS\SYSTEM32\DevMngr.vxd
2008-02-19 21:29 . 2008-02-19 21:29 <DIR> d-------- C:\Program Files\Zoom
2008-02-19 21:29 . 2006-04-06 15:21 598,528 --------- C:\WINDOWS\SYSTEM32\Atx45.ocx
2008-02-19 21:29 . 2006-04-06 15:21 221,184 --------- C:\WINDOWS\SYSTEM32\DartSock.dll
2008-02-19 21:29 . 2006-04-06 15:21 118,784 --------- C:\WINDOWS\SYSTEM32\DartTelnet.dll
2008-02-19 21:29 . 2007-04-11 16:31 17,403 --------- C:\WINDOWS\wwdslcfg.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-09 19:25 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-09 19:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-09 04:50 --------- d-----w C:\Program Files\Lavasoft
2008-03-09 04:49 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-08 20:30 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-03-08 20:30 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-03-08 20:30 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-03-08 20:30 --------- d-----w C:\Program Files\Symantec
2008-02-20 02:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2004-12-10 21:24 482 ----a-w C:\Program Files\SolidWorksswxJRNL.BAK
2004-09-22 20:18 16 ----a-w C:\Program Files\FILESDB.DAT
2004-09-22 20:17 99,610 ----a-w C:\Program Files\Uninst.isu
2004-09-22 20:17 3,072 ----a-w C:\Program Files\Cirmaker.dat
1999-05-11 17:21 1,337,856 ----a-w C:\Program Files\Cirmaker.exe
1999-05-10 16:05 582,507 ------w C:\Program Files\Device.lib
1999-05-04 16:14 61,952 ------w C:\Program Files\Toolwnd.dll
1999-05-03 14:37 1,445,888 ------w C:\Program Files\Wxspice.exe
1999-04-19 21:03 16,737 ------w C:\Program Files\Devicedb.dat
1999-04-13 15:32 222,720 ------w C:\Program Files\NConvert.dll
1998-09-03 17:50 568,754 ------w C:\Program Files\cirmaker.hlp
1998-08-19 17:20 111,112 ------w C:\Program Files\user.lib
1998-07-09 21:05 22,095 ------w C:\Program Files\Cirmaker.cnt
1997-07-22 17:08 2 ------w C:\Program Files\Hotkeydb.dat
1997-06-30 22:04 1,107 ------w C:\Program Files\Symboldb.dat
1994-03-22 12:50 766 ------w C:\Program Files\Help.ico
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"Steam"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-03-15 01:04 122933]
"CTSysVol"="C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 10:43 57344]
"P17Helper"="P17.dll" [2004-06-10 11:51 60928 C:\WINDOWS\SYSTEM32\P17.dll]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00 90112]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 05:00 132496]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 20:12 221184]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-28 19:21 180269]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-09-25 15:54 229952]
"IAAnotif"="C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-03-23 12:16 135168]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 01:01 110592]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-24 04:24 282624]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 20:15 290816]
"mmtask"="C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe" [2004-10-08 09:49 53248]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 11:43 53248]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 22:05 344064]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-28 22:51 107112]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-09-05 21:22 26248]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]
C:\Documents and Settings\joxaal\Start Menu\Programs\Startup\
PowerReg Scheduler.exe [2005-01-28 09:02:35 256000]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-21 21:30:38 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\LimeWire\\LimeWire 4.0.8\\LimeWire.exe"=
"C:\\Program Files\\Starcraft\\StarCraft.exe"=
"C:\\Program Files\\Valve\\Steam\\Steam.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\getafro1\\counter-strike\\hl.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Kazaa Lite K++\\KazaaLite.kpp"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\getafro1\\condition zero\\hl.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\getafro1\\condition zero deleted scenes\\hl.exe"=
"C:\\Program Files\\Microsoft Games\\Rise of Nations\\rise.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\User\\Half-Life 2\\hl2.exe"=
"C:\\Program Files\\Microsoft Games\\Rise of Nations\\nations.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-29 16:18:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-08 15:34:17 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - joxaal.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-09 14:35:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
.
**************************************************************************
.
Completion time: 2008-03-09 14:47:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-09 19:47:18
.
2007-12-12 10:03:44 --- E O F ---