hi can anyone help me get rid of this virus its really annoying now!
this is the log i have from one of the programs i was told to use hope it helps and that someone can give me some advice.
Cheers
ComboFix 08-09-05.12 - Glen 2008-09-09 17:43:34.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.632 [GMT 1:00]
Running from: C:\Documents and Settings\Glen\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-08-09 to 2008-09-09 )))))))))))))))))))))))))))))))
.
2008-09-09 17:30 . 2008-09-09 17:33 <DIR> d-------- C:\fixwareout
2008-09-08 17:59 . 2008-09-08 17:59 <DIR> d-------- C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\AVG7
2008-09-08 17:59 . 2008-09-09 09:00 <DIR> d-------- C:\Documents and Settings\Glen\Application Data\AVG7
2008-09-08 17:59 . 2008-09-08 17:59 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2008-09-08 17:47 . 2008-09-08 17:47 <DIR> d-------- C:\Program Files\wobnmnc
2008-09-08 17:47 . 2008-09-08 17:47 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\tmdyfuje
2008-09-08 17:40 . 2008-09-08 17:40 <DIR> d-------- C:\Documents and Settings\Glen\Application Data\AVSMedia
2008-09-08 17:40 . 2008-09-08 17:40 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\AVS4YOU
2008-09-08 17:39 . 2008-09-08 17:39 <DIR> d-------- C:\Program Files\Common Files\AVSMedia
2008-09-08 17:39 . 2008-09-08 17:39 <DIR> d-------- C:\Program Files\AVSMedia
2008-09-08 15:02 . 2008-09-08 15:02 <DIR> d-------- C:\Documents and Settings\Glen\Application Data\Ahead
2008-09-08 14:34 . 2008-09-08 14:34 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Elaborate Bytes
2008-09-08 14:30 . 2008-09-08 14:30 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SlySoft
2008-09-08 14:29 . 2008-09-08 14:44 <DIR> d-------- C:\Program Files\SlySoft
2008-09-08 14:29 . 2008-09-08 14:44 <DIR> d-------- C:\Program Files\Elaborate Bytes
2008-09-08 14:29 . 2008-09-08 14:29 0 --ahs---- C:\WINDOWS\S62EF0A17.tmp
2008-08-13 11:05 . 2008-05-01 15:33 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-13 11:04 . 2008-04-11 20:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-12 11:44 . 2008-08-12 11:46 <DIR> d-------- C:\WINDOWS\NV28442848.TMP
2008-08-12 11:43 . 2008-05-03 05:46 182,347 --a------ C:\WINDOWS\system32\nvapps.nvb
2008-08-12 11:42 . 2008-08-12 11:46 <DIR> d-------- C:\WINDOWS\NV7241024.TMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-09 11:06 --------- d-----w C:\Documents and Settings\Glen\Application Data\uTorrent
2008-09-08 17:42 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Avg7
2008-09-08 16:38 --------- d-----w C:\Program Files\Common Files\MGI Shared
2008-09-08 16:25 --------- d-----w C:\Program Files\Common Files\Nero
2008-09-08 16:25 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Nero
2008-09-02 18:00 --------- d-----w C:\Program Files\World of Warcraft
2008-08-08 11:18 --------- d-----w C:\Program Files\Realtek
2008-08-08 11:17 9,709,568 ----a-w C:\WINDOWS\RTLCPL.exe
2008-08-08 11:17 86,016 ----a-w C:\WINDOWS\SoundMan.exe
2008-08-08 11:17 69,632 ----a-w C:\WINDOWS\Alcmtr.exe
2008-08-08 11:17 520,192 ----a-w C:\WINDOWS\RtlExUpd.dll
2008-08-08 11:17 49,152 ----a-w C:\WINDOWS\system32\ChCfg.exe
2008-08-08 11:17 4,484,608 ----a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-08-08 11:17 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-08-08 11:17 2,879,488 ----a-w C:\WINDOWS\SkyTel.exe
2008-08-08 11:17 2,808,832 ----a-w C:\WINDOWS\alcwzrd.exe
2008-08-08 11:17 2,157,568 ----a-w C:\WINDOWS\MicCal.exe
2008-08-08 11:17 16,125,440 ----a-w C:\WINDOWS\RTHDCPL.exe
2008-08-08 11:17 1,191,936 ----a-w C:\WINDOWS\RtlUpd.exe
2008-08-06 20:01 --------- d-----w C:\Documents and Settings\Glen\Application Data\Ventrilo
2008-08-06 19:57 --------- d-----w C:\Program Files\Ventrilo
2008-08-06 19:57 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-05 09:26 --------- d-----w C:\Program Files\MSN Messenger
2008-07-31 20:07 --------- d-----w C:\Program Files\Sky Broadband
2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 21:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 21:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-16 17:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-11 17:11 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-03-25 15:54 32 ----a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"kdx"="C:\WINDOWS\kdx\KHost.exe" [2007-05-11 2236416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-03 13529088]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-03 86016]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-09-09 579584]
"nwiz"="nwiz.exe" [2008-05-03 C:\WINDOWS\system32\nwiz.exe]
"SkyTel"="SkyTel.EXE" [2008-08-08 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-08-08 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-09-08 219136]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"AppSrv"= {01121076-D059-8A75-D236-0069190EE0D1} - C:\Program Files\wobnmnc\AppSrv.dll [2008-09-08 102400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"C:\\WINDOWS\\kdx\\KHost.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
S2 Ca536av;DigitalCam Pro Video Camera Device;C:\WINDOWS\system32\Drivers\Ca536av.sys [2004-05-22 517131]
S3 usbaucmd;usbaucmd;C:\WINDOWS\system32\drivers\usbaucmd.sys [ ]
S3 usbaufl;usbaufl;C:\WINDOWS\system32\drivers\usbaufl.sys [ ]
S3 USBCamera;DigitalCam Pro Still Camera Device;C:\WINDOWS\system32\Drivers\Bulk536.sys [2003-05-14 11048]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Glen\Application Data\Mozilla\Firefox\Profiles\r5sqs9m3.default\
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-09 17:45:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-09 17:45:51
ComboFix-quarantined-files.txt 2008-09-09 16:45:49
ComboFix2.txt 2008-09-09 16:21:09
ComboFix3.txt 2008-09-08 18:01:06
Pre-Run: 176,175,800,320 bytes free
Post-Run: 176,164,450,304 bytes free
148 --- E O F --- 2008-08-13 21:41:02