While following your instructions computer rebooted and the following message appeared
nircmd.cfexe-unable to locate component: "This application has failed to start because ConnAPI.DLL was not found. Re-installing the application may fix the problem.
Here are the logs:
ComboFix 07-08-30.3 - "Sonia" 2007-09-03 19:42:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.569 [GMT 1:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Grace\APPLIC~1\macromedia\Flash Player\#SharedObjects\HVYZW97E\iforex.com
C:\DOCUME~1\Grace\APPLIC~1\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\WINDOWS\cookies.ini
C:\WINDOWS\DOWNLO~1.\TriJinx.1.0.0.67
C:\WINDOWS\system32\aoxwylcb.exe
C:\WINDOWS\system32\arqarisa.exe
C:\WINDOWS\system32\awvvs.dll
C:\WINDOWS\system32\bxbkluyn.exe
C:\WINDOWS\system32\dnruslpd.exe
C:\WINDOWS\system32\gypnkfnt.exe
C:\WINDOWS\system32\irydlitt.exe
C:\WINDOWS\system32\jayudaqp.exe
C:\WINDOWS\system32\kfgovxpu.exe
C:\WINDOWS\system32\nkhgkefg.exe
C:\WINDOWS\system32\nvs2.inf
C:\WINDOWS\system32\oobpjfwl.exe
C:\WINDOWS\system32\rrdmbvqh.exe
C:\WINDOWS\system32\svttgoer.exe
C:\WINDOWS\system32\svvwa.bak1
C:\WINDOWS\system32\svvwa.bak2
C:\WINDOWS\system32\svvwa.ini
C:\WINDOWS\system32\svvwa.ini2
C:\WINDOWS\system32\svvwa.tmp
C:\WINDOWS\system32\tswivcie.exe
C:\WINDOWS\system32\uvwabnvv.dll
C:\WINDOWS\system32\xfacebld.exe
C:\WINDOWS\system32\xffistgu.exe
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-08-03 to 2007-09-03 )))))))))))))))))))))))))))))))
2007-09-03 19:41 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-09-03 07:32 <DIR> d-------- C:\Program Files\Trend Micro
2007-09-02 22:12 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-09-02 22:12 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-08-31 20:00 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-08-31 18:57 4,746 --a------ C:\WINDOWS\system32\tmp.reg
2007-08-30 22:45 <DIR> d-------- C:\WINDOWS\pss
2007-08-30 22:31 <DIR> d-------- C:\Program Files\RogueRemover FREE
2007-08-29 20:02 1,152 --a------ C:\WINDOWS\system32\windrv.sys
2007-08-29 20:02 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2007-08-05 09:21 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-05 09:12 <DIR> d-------- C:\Program Files\Lavasoft
2007-08-05 09:12 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-08-05 09:11 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-09-03 19:51 --------- d-------- C:\Program Files\dl_cats
2007-09-03 19:47 978839 --ahs---- C:\WINDOWS\system32\svvwa.ini2
2007-09-02 20:17 9344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-09-02 20:17 8320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-30 22:37 --------- d-------- C:\Program Files\Yahoo!
2007-08-05 08:28 --------- d-------- C:\Program Files\Logitech
2007-08-05 08:28 --------- d-------- C:\Program Files\Common Files\InstallShield
2007-08-05 08:24 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-05 08:24 --------- d-------- C:\Program Files\Dynamic Toolbar
2007-08-05 08:23 --------- d-------- C:\Program Files\Skype
2007-08-02 22:16 --------- d-------- C:\Program Files\CCleaner
2007-08-02 22:16 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 19:19 271224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 --a------ C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\dllcache\wups.dll
2007-07-29 18:56 --------- d-------- C:\DOCUME~1\Mark\APPLIC~1\Skype
2007-07-29 10:15 --------- d-------- C:\DOCUME~1\Grace\APPLIC~1\IM-Names
2007-07-28 20:14 377876 --a------ C:\WINDOWS\system32\nsaeijvi.dll
2007-07-19 07:59 3583488 --a------ C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-13 00:31 765952 --a------ C:\WINDOWS\system32\dllcache\vgx.dll
2007-07-11 18:03 6580 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-07-11 18:03 56 -r-hs---- C:\WINDOWS\system32\44F68E9285.sys
2007-07-11 18:03 --------- d-------- C:\DOCUME~1\Grace\APPLIC~1\Corel Photo Album
2007-07-07 09:06 --------- d-------- C:\DOCUME~1\Lauren\APPLIC~1\IM-Names
2007-06-27 15:34 823808 --a------ C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 15:34 671232 --a------ C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 15:34 6058496 --a------ C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 15:34 52224 --a------ C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 15:34 477696 --a------ C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 15:34 459264 --a------ C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 15:34 44544 --a------ C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 15:34 384512 --a------ C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 15:34 383488 --a------ C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 15:34 27648 --a------ C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 15:34 267776 --a------ C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 15:34 232960 --a------ C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 15:34 230400 --a------ C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 15:34 193024 --a------ C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 15:34 153088 --a------ C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 15:34 132608 --a------ C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 15:34 124928 --a------ C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 15:34 1152000 --a------ C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 15:34 105984 --a------ C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 15:34 102400 --a------ C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 09:27 63488 --a------ C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 09:27 625152 --a------ C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 09:27 13824 --a------ C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 08:00 161792 --a------ C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-26 07:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-26 07:08 1104896 --a------ C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 14:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-19 14:31 282112 --a------ C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-13 11:23 1033216 --a------ C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 11:23 1033216 --a------ C:\WINDOWS\explorer.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E7BD74F-2B8D-469E-A0E8-F479B685FA7D}]
C:\WINDOWS\system32\pbukv2.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{4E7BD74F-2B8D-469E-A0E8-F479B685FA7D}"= C:\WINDOWS\system32\pbukv2.dll [ ]
[HKEY_CLASSES_ROOT\CLSID\{4E7BD74F-2B8D-469E-A0E8-F479B685FA7D}]
[HKEY_CLASSES_ROOT\pbukv2.PBUKV2]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-10 15:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 15:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 15:00]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 05:04]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 16:10 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-09-10 19:29 C:\WINDOWS\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2004-09-15 12:20 C:\WINDOWS\ALCWZRD.EXE]
"ATIPTA"="C:\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 22:10]
"ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 11:31]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-03-19 13:12]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-08-28 14:14]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2006-10-03 22:14]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-11-08 14:27]
"FaxCenterServer"="C:\Program Files\Dell PC Fax\fm3032.exe" [2006-06-15 11:03]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-09-01 14:04]
"ISUSPM Startup"="c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" []
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44]
"dlcxmon.exe"="C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe" [2006-06-14 13:51]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 926\memcard.exe" [2006-06-27 12:34]
"DLCXCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-06-07 17:17]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15:00]
"EzStatus"="C:\Apps\EZHome\EZStatus.exe" [2004-12-20 20:03]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-07 17:58]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"EzStatus"=C:\Apps\EZHome\EZStatus.exe
"PcSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
R1 vcsmpdrv;vcsmpdrv;C:\WINDOWS\system32\DRIVERS\vcsmpdrv.sys
R2 VCSSecS;Virtual CD v4 Security service (SDK - Version);C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys
R3 dlcx_device;dlcx_device;C:\WINDOWS\system32\dlcxcoms.exe -service
R3 LVPrcMon;Logitech LVPrcMon Driver;\??\C:\WINDOWS\system32\drivers\LVPrcMon.sys
S3 ATHFMWDL;NETGEAR WPN111 Bootloader driver;C:\WINDOWS\system32\Drivers\athwpn.sys
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\system32\DNINDIS5.SYS
S3 grmnusb;grmnusb;C:\WINDOWS\system32\drivers\grmnusb.sys
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;C:\WINDOWS\system32\DRIVERS\WPN111.sys
Contents of the 'Scheduled Tasks' folder
2007-06-30 17:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-09-03 18:35:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
2006-08-17 19:05:50 C:\WINDOWS\Tasks\Registration reminder 2.job - C:\WINDOWS\system32\OOBE\oobebaln.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-03 19:51:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-09-03 19:52:28 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-03 19:52
--- E O F ---