here is a DDS log
DDS (Ver_09-07-30.01) - NTFSx86
Run by harry at 12:55:19.85 on Sat 08/29/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1264 [GMT -6:00]
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
D:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
D:\WINDOWS\System32\svchost.exe -k netsvcs
D:\Program Files\Intel\Wireless\Bin\EvtEng.exe
D:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Avira\AntiVir Desktop\sched.exe
D:\Program Files\Avira\AntiVir Desktop\avguard.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
D:\WINDOWS\system32\svchost.exe -k imgsvc
D:\WINDOWS\system32\wscntfy.exe
D:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
D:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
D:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
D:\WINDOWS\System32\svchost.exe -k HTTPFilter
D:\WINDOWS\system32\igfxpers.exe
D:\WINDOWS\system32\WDBtnMgr.exe
D:\WINDOWS\RTHDCPL.EXE
D:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
D:\WINDOWS\system32\notepad.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Java\jre6\bin\java.exe
D:\Documents and Settings\harry\My Documents\Downloads\Applications\Malware Apps\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://mail.google.com/mail/?ui=1
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [Uniblue RegistryBooster 2] d:\program files\uniblue\registrybooster 2\RegistryBooster.exe /S
mRun: [IntelZeroConfig] "d:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "d:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [EOUApp] "d:\program files\intel\wireless\bin\EOUWiz.exe"
mRun: [igfxtray] d:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] d:\windows\system32\hkcmd.exe
mRun: [igfxpers] d:\windows\system32\igfxpers.exe
mRun: [QuickTime Task] "d:\program files\quicktime\qttask.exe" -atboottime
mRun: [WD Button Manager] WDBtnMgr.exe
mRun: [eDataSecurity Loader] c:\acer\empowering technology\edatasecurity\eDSloader.exe
mRun: [Adobe Photo Downloader] "d:\program files\adobe\photoshop elements 5.0\apdproxy.exe"
mRun: [ISUSPM] "d:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [NeroFilterCheck] d:\windows\system32\NeroCheck.exe
mRun: [avgnt] "d:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [SunJavaUpdateSched] "d:\program files\java\jre6\bin\jusched.exe"
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe
Trusted Zone: beatport.com\www
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553525000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - d:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;d:\program files\avira\antivir desktop\avgio.sys [2009-8-25 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;d:\program files\avira\antivir desktop\sched.exe [2009-8-25 108289]
R2 AntiVirService;Avira AntiVir Guard;d:\program files\avira\antivir desktop\avguard.exe [2009-8-25 185089]
R2 avgntflt;avgntflt;d:\windows\system32\drivers\avgntflt.sys [2009-8-17 55656]
R2 EpmPsd;Acer EPM Power Scheme Driver;d:\windows\system32\drivers\epm-psd.sys [2007-4-14 4096]
R2 EpmShd;Acer EPM System Hardware Driver;d:\windows\system32\drivers\epm-shd.sys [2007-4-14 78208]
S3 a8djavs;a8djavs;d:\windows\system32\drivers\a8djavs.sys [2009-4-17 25600]
S3 a8djusb;a8djusb;d:\windows\system32\drivers\a8djusb.sys [2009-4-17 85504]
S3 Ambfilt;Ambfilt;d:\windows\system32\drivers\Ambfilt.sys [2009-4-7 1684736]
S3 IKFileSec;File Security Driver;d:\windows\system32\drivers\ikfilesec.sys [2009-8-26 42376]
S3 IKSysFlt;System Filter Driver;d:\windows\system32\drivers\iksysflt.sys [2009-8-26 66952]
S3 IKSysSec;System Security Driver;d:\windows\system32\drivers\iksyssec.sys [2009-8-26 81288]
S3 lv321av;Logitech USB PC Camera (VC0321);d:\windows\system32\drivers\lv321av.sys --> d:\windows\system32\drivers\lv321av.sys [?]
S3 MADFU;MADFU;d:\windows\system32\drivers\MADFU.sys [2007-4-14 16512]
S3 MAUSBML;Service for M-Audio Conectiv (WDM);d:\windows\system32\drivers\mausbcv.sys --> d:\windows\system32\drivers\mausbcv.sys [?]
S3 sdAuxService;PC Tools Auxiliary Service;d:\program files\spyware doctor\pctsAuxs.exe [2009-8-26 356920]
S3 sdCoreService;PC Tools Security Service;d:\program files\spyware doctor\pctsSvc.exe [2009-8-26 1072008]
=============== Created Last 30 ================
2009-08-29 09:55 <DIR> --ds---- D:\ComboFix
2009-08-29 07:07 <DIR> -cd----- d:\windows\system32\dllcache\cache
2009-08-29 06:59 <DIR> a-dshr-- D:\cmdcons
2009-08-29 06:51 229,376 a------- d:\windows\PEV.exe
2009-08-29 06:51 161,792 a------- d:\windows\SWREG.exe
2009-08-29 06:51 98,816 a------- d:\windows\sed.exe
2009-08-26 11:20 81,288 a------- d:\windows\system32\drivers\iksyssec.sys
2009-08-26 11:20 66,952 a------- d:\windows\system32\drivers\iksysflt.sys
2009-08-26 11:20 42,376 a------- d:\windows\system32\drivers\ikfilesec.sys
2009-08-26 11:20 29,576 a------- d:\windows\system32\drivers\kcom.sys
2009-08-26 11:20 <DIR> --d----- d:\program files\Spyware Doctor
2009-08-26 11:20 <DIR> --d----- d:\docume~1\harry\applic~1\PC Tools
2009-08-25 10:27 34,296 a------- d:\windows\system32\drivers\mbamcatchme.sys
2009-08-25 10:27 17,144 a------- d:\windows\system32\drivers\mbam.sys
2009-08-25 10:27 <DIR> --d----- d:\program files\Malwarebytes' Anti-Malware
2009-08-25 03:47 <DIR> --d----- d:\program files\Avira
2009-08-25 03:47 <DIR> --d----- d:\docume~1\alluse~1\applic~1\Avira
2009-08-25 01:59 <DIR> --d----- d:\program files\fluffy
2009-08-24 03:27 1,152 a------- d:\windows\system32\windrv.sys
2009-08-24 03:06 <DIR> --d----- d:\docume~1\harry\applic~1\GetRightToGo
2009-08-17 12:07 55,656 a------- d:\windows\system32\drivers\avgntflt.sys
2009-08-11 00:25 <DIR> --d----- d:\program files\common files\Windows Live
==================== Find3M ====================
2009-07-25 05:23 411,368 a------- d:\windows\system32\deploytk.dll
2007-10-13 13:58 167 ac------ d:\documents and settings\harry\udownload.dat
2004-02-04 20:53 24,070,405 a------- d:\documents and settings\harry\nero6303.exe
2004-01-31 20:54 331,776 ac------ d:\windows\inf\pdfinst2.exe
============= FINISH: 12:55:53.82 ===============
and the combo log
ComboFix 09-08-28.05 - harry 08/29/2009 9:56.7.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1618 [GMT -6:00]
Running from: d:\documents and settings\harry\Desktop\ComboFix.exe
Command switches used :: d:\documents and settings\harry\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FILE ::
"d:\windows\system32\braviax.VIR"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\documents and settings\harry\Application Data\uTorrent
d:\documents and settings\harry\Application Data\uTorrent\dht.dat
d:\documents and settings\harry\Application Data\uTorrent\resume.dat
d:\documents and settings\harry\Application Data\uTorrent\resume.dat.old
d:\documents and settings\harry\Application Data\uTorrent\rss.dat
d:\documents and settings\harry\Application Data\uTorrent\settings.dat
d:\documents and settings\harry\Application Data\uTorrent\settings.dat.old
d:\documents and settings\harry\Application Data\uTorrent\UK #1 Bhangra Hits [Pao-Bhangra.com][Hub][Oct 05].torrent
d:\windows\system32\braviax.VIR
.
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-29 )))))))))))))))))))))))))))))))
.
2009-08-26 17:20 . 2008-06-11 03:22 81288 ----a-w- d:\windows\system32\drivers\iksyssec.sys
2009-08-26 17:20 . 2008-06-02 21:19 29576 ----a-w- d:\windows\system32\drivers\kcom.sys
2009-08-26 17:20 . 2008-06-02 21:19 66952 ----a-w- d:\windows\system32\drivers\iksysflt.sys
2009-08-26 17:20 . 2008-06-02 21:19 42376 ----a-w- d:\windows\system32\drivers\ikfilesec.sys
2009-08-26 17:20 . 2009-08-26 17:20 -------- d-----w- d:\program files\Spyware Doctor
2009-08-26 17:20 . 2009-08-26 17:20 -------- d-----w- d:\documents and settings\harry\Application Data\PC Tools
2009-08-26 07:43 . 2009-08-26 07:43 152576 ----a-w- d:\documents and settings\harry\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-25 16:27 . 2009-08-25 17:01 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2009-08-25 16:27 . 2008-06-19 23:48 34296 ----a-w- d:\windows\system32\drivers\mbamcatchme.sys
2009-08-25 16:27 . 2008-06-19 23:47 17144 ----a-w- d:\windows\system32\drivers\mbam.sys
2009-08-25 09:47 . 2009-03-30 16:33 96104 ----a-w- d:\windows\system32\drivers\avipbb.sys
2009-08-25 09:47 . 2009-02-13 18:29 22360 ----a-w- d:\windows\system32\drivers\avgntmgr.sys
2009-08-25 09:47 . 2009-02-13 18:17 45416 ----a-w- d:\windows\system32\drivers\avgntdd.sys
2009-08-25 09:47 . 2009-08-25 09:47 -------- d-----w- d:\program files\Avira
2009-08-25 09:47 . 2009-08-25 09:47 -------- d-----w- d:\documents and settings\All Users\Application Data\Avira
2009-08-25 07:59 . 2009-08-25 08:01 -------- d-----w- d:\program files\fluffy
2009-08-24 09:27 . 2009-08-24 09:27 1152 ----a-w- d:\windows\system32\windrv.sys
2009-08-24 09:06 . 2009-08-24 09:09 -------- d-----w- d:\documents and settings\harry\Application Data\GetRightToGo
2009-08-17 18:07 . 2009-07-28 22:33 55656 ----a-w- d:\windows\system32\drivers\avgntflt.sys
2009-08-11 06:25 . 2009-08-11 06:25 -------- d-----w- d:\program files\Common Files\Windows Live
2009-08-11 06:18 . 2009-08-11 06:18 15240 ----a-w- d:\documents and settings\harry\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-29 12:38 . 2007-09-11 17:39 -------- d---a-w- d:\documents and settings\All Users\Application Data\TEMP
2009-08-26 17:13 . 2008-05-13 17:42 -------- d-----w- d:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-26 07:43 . 2009-01-08 17:48 -------- d-----w- d:\program files\Java
2009-08-25 06:54 . 2008-05-03 16:25 -------- d-----w- d:\program files\Common Files\PC Tools
2009-08-24 15:43 . 2008-10-21 18:14 -------- d-----w- d:\program files\BizWare Magic DATEwise
2009-08-22 04:15 . 2007-10-12 23:44 -------- d-----w- d:\program files\PC Tools AntiVirus
2009-07-25 11:23 . 2009-01-08 17:49 411368 ----a-w- d:\windows\system32\deploytk.dll
2009-07-14 13:08 . 2008-10-23 08:32 -------- d-----w- d:\documents and settings\harry\Application Data\Apple Computer
2009-06-19 22:55 . 2009-06-19 22:55 152576 ----a-w- d:\documents and settings\harry\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-08-29_13.04.41 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-04 12:00 . 2009-08-28 20:45 58800 d:\windows\system32\perfc009.dat
+ 2004-08-04 12:00 . 2009-08-29 13:08 58800 d:\windows\system32\perfc009.dat
+ 2004-08-04 12:00 . 2009-08-29 13:08 392626 d:\windows\system32\perfh009.dat
- 2004-08-04 12:00 . 2009-08-28 20:45 392626 d:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Uniblue RegistryBooster 2"="d:\program files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"="d:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
"IntelWireless"="d:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
"EOUApp"="d:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2005-12-28 569413]
"igfxtray"="d:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="d:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="d:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"QuickTime Task"="d:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [BU]
"Adobe Photo Downloader"="d:\program files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [BU]
"ISUSPM"="d:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [BU]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"NeroFilterCheck"="d:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"avgnt"="d:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"WD Button Manager"="WDBtnMgr.exe" - d:\windows\system32\WDBtnMgr.exe [2008-03-05 364544]
"RTHDCPL"="RTHDCPL.EXE" - d:\windows\RTHDCPL.EXE [2009-03-27 17567744]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Ares\\Ares.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;d:\program files\Avira\AntiVir Desktop\sched.exe [8/25/2009 3:47 AM 108289]
S3 Ambfilt;Ambfilt;d:\windows\system32\drivers\Ambfilt.sys [4/7/2009 12:23 PM 1684736]
S3 lv321av;Logitech USB PC Camera (VC0321);d:\windows\system32\DRIVERS\lv321av.sys --> d:\windows\system32\DRIVERS\lv321av.sys [?]
S3 MADFU;MADFU;d:\windows\system32\drivers\MADFU.sys [4/14/2007 6:39 PM 16512]
S3 MAUSBML;Service for M-Audio Conectiv (WDM);d:\windows\system32\DRIVERS\mausbcv.sys --> d:\windows\system32\DRIVERS\mausbcv.sys [?]
S3 sdAuxService;PC Tools Auxiliary Service;d:\program files\Spyware Doctor\pctsAuxs.exe [8/26/2009 11:20 AM 356920]
--- Other Services/Drivers In Memory ---
*Deregistered* - wdyafakj
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://mail.google.com/mail/?ui=1
Trusted Zone: beatport.com\www
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-29 09:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-08-29 10:00
ComboFix-quarantined-files.txt 2009-08-29 16:00
ComboFix2.txt 2009-08-29 13:08
ComboFix3.txt 2008-07-14 07:17
ComboFix4.txt 2008-06-28 14:51
ComboFix5.txt 2009-08-29 15:55
Pre-Run: 28,108,300,288 bytes free
Post-Run: 28,096,512,000 bytes free
131 --- E O F --- 2007-12-21 18:18
I'm running the ksper scanner and did it wrong the first time it wouldnt save out the log..anways it said it found two threats...i'll post the findings when the scan is done
DDS (Ver_09-07-30.01) - NTFSx86
Run by harry at 12:55:19.85 on Sat 08/29/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1264 [GMT -6:00]
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
D:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
D:\WINDOWS\System32\svchost.exe -k netsvcs
D:\Program Files\Intel\Wireless\Bin\EvtEng.exe
D:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Avira\AntiVir Desktop\sched.exe
D:\Program Files\Avira\AntiVir Desktop\avguard.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
D:\WINDOWS\system32\svchost.exe -k imgsvc
D:\WINDOWS\system32\wscntfy.exe
D:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
D:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
D:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
D:\WINDOWS\System32\svchost.exe -k HTTPFilter
D:\WINDOWS\system32\igfxpers.exe
D:\WINDOWS\system32\WDBtnMgr.exe
D:\WINDOWS\RTHDCPL.EXE
D:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
D:\WINDOWS\system32\notepad.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Java\jre6\bin\java.exe
D:\Documents and Settings\harry\My Documents\Downloads\Applications\Malware Apps\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://mail.google.com/mail/?ui=1
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [Uniblue RegistryBooster 2] d:\program files\uniblue\registrybooster 2\RegistryBooster.exe /S
mRun: [IntelZeroConfig] "d:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "d:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [EOUApp] "d:\program files\intel\wireless\bin\EOUWiz.exe"
mRun: [igfxtray] d:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] d:\windows\system32\hkcmd.exe
mRun: [igfxpers] d:\windows\system32\igfxpers.exe
mRun: [QuickTime Task] "d:\program files\quicktime\qttask.exe" -atboottime
mRun: [WD Button Manager] WDBtnMgr.exe
mRun: [eDataSecurity Loader] c:\acer\empowering technology\edatasecurity\eDSloader.exe
mRun: [Adobe Photo Downloader] "d:\program files\adobe\photoshop elements 5.0\apdproxy.exe"
mRun: [ISUSPM] "d:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [NeroFilterCheck] d:\windows\system32\NeroCheck.exe
mRun: [avgnt] "d:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [SunJavaUpdateSched] "d:\program files\java\jre6\bin\jusched.exe"
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe
Trusted Zone: beatport.com\www
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553525000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - d:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;d:\program files\avira\antivir desktop\avgio.sys [2009-8-25 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;d:\program files\avira\antivir desktop\sched.exe [2009-8-25 108289]
R2 AntiVirService;Avira AntiVir Guard;d:\program files\avira\antivir desktop\avguard.exe [2009-8-25 185089]
R2 avgntflt;avgntflt;d:\windows\system32\drivers\avgntflt.sys [2009-8-17 55656]
R2 EpmPsd;Acer EPM Power Scheme Driver;d:\windows\system32\drivers\epm-psd.sys [2007-4-14 4096]
R2 EpmShd;Acer EPM System Hardware Driver;d:\windows\system32\drivers\epm-shd.sys [2007-4-14 78208]
S3 a8djavs;a8djavs;d:\windows\system32\drivers\a8djavs.sys [2009-4-17 25600]
S3 a8djusb;a8djusb;d:\windows\system32\drivers\a8djusb.sys [2009-4-17 85504]
S3 Ambfilt;Ambfilt;d:\windows\system32\drivers\Ambfilt.sys [2009-4-7 1684736]
S3 IKFileSec;File Security Driver;d:\windows\system32\drivers\ikfilesec.sys [2009-8-26 42376]
S3 IKSysFlt;System Filter Driver;d:\windows\system32\drivers\iksysflt.sys [2009-8-26 66952]
S3 IKSysSec;System Security Driver;d:\windows\system32\drivers\iksyssec.sys [2009-8-26 81288]
S3 lv321av;Logitech USB PC Camera (VC0321);d:\windows\system32\drivers\lv321av.sys --> d:\windows\system32\drivers\lv321av.sys [?]
S3 MADFU;MADFU;d:\windows\system32\drivers\MADFU.sys [2007-4-14 16512]
S3 MAUSBML;Service for M-Audio Conectiv (WDM);d:\windows\system32\drivers\mausbcv.sys --> d:\windows\system32\drivers\mausbcv.sys [?]
S3 sdAuxService;PC Tools Auxiliary Service;d:\program files\spyware doctor\pctsAuxs.exe [2009-8-26 356920]
S3 sdCoreService;PC Tools Security Service;d:\program files\spyware doctor\pctsSvc.exe [2009-8-26 1072008]
=============== Created Last 30 ================
2009-08-29 09:55 <DIR> --ds---- D:\ComboFix
2009-08-29 07:07 <DIR> -cd----- d:\windows\system32\dllcache\cache
2009-08-29 06:59 <DIR> a-dshr-- D:\cmdcons
2009-08-29 06:51 229,376 a------- d:\windows\PEV.exe
2009-08-29 06:51 161,792 a------- d:\windows\SWREG.exe
2009-08-29 06:51 98,816 a------- d:\windows\sed.exe
2009-08-26 11:20 81,288 a------- d:\windows\system32\drivers\iksyssec.sys
2009-08-26 11:20 66,952 a------- d:\windows\system32\drivers\iksysflt.sys
2009-08-26 11:20 42,376 a------- d:\windows\system32\drivers\ikfilesec.sys
2009-08-26 11:20 29,576 a------- d:\windows\system32\drivers\kcom.sys
2009-08-26 11:20 <DIR> --d----- d:\program files\Spyware Doctor
2009-08-26 11:20 <DIR> --d----- d:\docume~1\harry\applic~1\PC Tools
2009-08-25 10:27 34,296 a------- d:\windows\system32\drivers\mbamcatchme.sys
2009-08-25 10:27 17,144 a------- d:\windows\system32\drivers\mbam.sys
2009-08-25 10:27 <DIR> --d----- d:\program files\Malwarebytes' Anti-Malware
2009-08-25 03:47 <DIR> --d----- d:\program files\Avira
2009-08-25 03:47 <DIR> --d----- d:\docume~1\alluse~1\applic~1\Avira
2009-08-25 01:59 <DIR> --d----- d:\program files\fluffy
2009-08-24 03:27 1,152 a------- d:\windows\system32\windrv.sys
2009-08-24 03:06 <DIR> --d----- d:\docume~1\harry\applic~1\GetRightToGo
2009-08-17 12:07 55,656 a------- d:\windows\system32\drivers\avgntflt.sys
2009-08-11 00:25 <DIR> --d----- d:\program files\common files\Windows Live
==================== Find3M ====================
2009-07-25 05:23 411,368 a------- d:\windows\system32\deploytk.dll
2007-10-13 13:58 167 ac------ d:\documents and settings\harry\udownload.dat
2004-02-04 20:53 24,070,405 a------- d:\documents and settings\harry\nero6303.exe
2004-01-31 20:54 331,776 ac------ d:\windows\inf\pdfinst2.exe
============= FINISH: 12:55:53.82 ===============
and the combo log
ComboFix 09-08-28.05 - harry 08/29/2009 9:56.7.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1618 [GMT -6:00]
Running from: d:\documents and settings\harry\Desktop\ComboFix.exe
Command switches used :: d:\documents and settings\harry\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FILE ::
"d:\windows\system32\braviax.VIR"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\documents and settings\harry\Application Data\uTorrent
d:\documents and settings\harry\Application Data\uTorrent\dht.dat
d:\documents and settings\harry\Application Data\uTorrent\resume.dat
d:\documents and settings\harry\Application Data\uTorrent\resume.dat.old
d:\documents and settings\harry\Application Data\uTorrent\rss.dat
d:\documents and settings\harry\Application Data\uTorrent\settings.dat
d:\documents and settings\harry\Application Data\uTorrent\settings.dat.old
d:\documents and settings\harry\Application Data\uTorrent\UK #1 Bhangra Hits [Pao-Bhangra.com][Hub][Oct 05].torrent
d:\windows\system32\braviax.VIR
.
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-29 )))))))))))))))))))))))))))))))
.
2009-08-26 17:20 . 2008-06-11 03:22 81288 ----a-w- d:\windows\system32\drivers\iksyssec.sys
2009-08-26 17:20 . 2008-06-02 21:19 29576 ----a-w- d:\windows\system32\drivers\kcom.sys
2009-08-26 17:20 . 2008-06-02 21:19 66952 ----a-w- d:\windows\system32\drivers\iksysflt.sys
2009-08-26 17:20 . 2008-06-02 21:19 42376 ----a-w- d:\windows\system32\drivers\ikfilesec.sys
2009-08-26 17:20 . 2009-08-26 17:20 -------- d-----w- d:\program files\Spyware Doctor
2009-08-26 17:20 . 2009-08-26 17:20 -------- d-----w- d:\documents and settings\harry\Application Data\PC Tools
2009-08-26 07:43 . 2009-08-26 07:43 152576 ----a-w- d:\documents and settings\harry\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-25 16:27 . 2009-08-25 17:01 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2009-08-25 16:27 . 2008-06-19 23:48 34296 ----a-w- d:\windows\system32\drivers\mbamcatchme.sys
2009-08-25 16:27 . 2008-06-19 23:47 17144 ----a-w- d:\windows\system32\drivers\mbam.sys
2009-08-25 09:47 . 2009-03-30 16:33 96104 ----a-w- d:\windows\system32\drivers\avipbb.sys
2009-08-25 09:47 . 2009-02-13 18:29 22360 ----a-w- d:\windows\system32\drivers\avgntmgr.sys
2009-08-25 09:47 . 2009-02-13 18:17 45416 ----a-w- d:\windows\system32\drivers\avgntdd.sys
2009-08-25 09:47 . 2009-08-25 09:47 -------- d-----w- d:\program files\Avira
2009-08-25 09:47 . 2009-08-25 09:47 -------- d-----w- d:\documents and settings\All Users\Application Data\Avira
2009-08-25 07:59 . 2009-08-25 08:01 -------- d-----w- d:\program files\fluffy
2009-08-24 09:27 . 2009-08-24 09:27 1152 ----a-w- d:\windows\system32\windrv.sys
2009-08-24 09:06 . 2009-08-24 09:09 -------- d-----w- d:\documents and settings\harry\Application Data\GetRightToGo
2009-08-17 18:07 . 2009-07-28 22:33 55656 ----a-w- d:\windows\system32\drivers\avgntflt.sys
2009-08-11 06:25 . 2009-08-11 06:25 -------- d-----w- d:\program files\Common Files\Windows Live
2009-08-11 06:18 . 2009-08-11 06:18 15240 ----a-w- d:\documents and settings\harry\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-29 12:38 . 2007-09-11 17:39 -------- d---a-w- d:\documents and settings\All Users\Application Data\TEMP
2009-08-26 17:13 . 2008-05-13 17:42 -------- d-----w- d:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-26 07:43 . 2009-01-08 17:48 -------- d-----w- d:\program files\Java
2009-08-25 06:54 . 2008-05-03 16:25 -------- d-----w- d:\program files\Common Files\PC Tools
2009-08-24 15:43 . 2008-10-21 18:14 -------- d-----w- d:\program files\BizWare Magic DATEwise
2009-08-22 04:15 . 2007-10-12 23:44 -------- d-----w- d:\program files\PC Tools AntiVirus
2009-07-25 11:23 . 2009-01-08 17:49 411368 ----a-w- d:\windows\system32\deploytk.dll
2009-07-14 13:08 . 2008-10-23 08:32 -------- d-----w- d:\documents and settings\harry\Application Data\Apple Computer
2009-06-19 22:55 . 2009-06-19 22:55 152576 ----a-w- d:\documents and settings\harry\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-08-29_13.04.41 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-04 12:00 . 2009-08-28 20:45 58800 d:\windows\system32\perfc009.dat
+ 2004-08-04 12:00 . 2009-08-29 13:08 58800 d:\windows\system32\perfc009.dat
+ 2004-08-04 12:00 . 2009-08-29 13:08 392626 d:\windows\system32\perfh009.dat
- 2004-08-04 12:00 . 2009-08-28 20:45 392626 d:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Uniblue RegistryBooster 2"="d:\program files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"="d:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
"IntelWireless"="d:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
"EOUApp"="d:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2005-12-28 569413]
"igfxtray"="d:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="d:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="d:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"QuickTime Task"="d:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [BU]
"Adobe Photo Downloader"="d:\program files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [BU]
"ISUSPM"="d:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [BU]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"NeroFilterCheck"="d:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"avgnt"="d:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"WD Button Manager"="WDBtnMgr.exe" - d:\windows\system32\WDBtnMgr.exe [2008-03-05 364544]
"RTHDCPL"="RTHDCPL.EXE" - d:\windows\RTHDCPL.EXE [2009-03-27 17567744]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Ares\\Ares.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;d:\program files\Avira\AntiVir Desktop\sched.exe [8/25/2009 3:47 AM 108289]
S3 Ambfilt;Ambfilt;d:\windows\system32\drivers\Ambfilt.sys [4/7/2009 12:23 PM 1684736]
S3 lv321av;Logitech USB PC Camera (VC0321);d:\windows\system32\DRIVERS\lv321av.sys --> d:\windows\system32\DRIVERS\lv321av.sys [?]
S3 MADFU;MADFU;d:\windows\system32\drivers\MADFU.sys [4/14/2007 6:39 PM 16512]
S3 MAUSBML;Service for M-Audio Conectiv (WDM);d:\windows\system32\DRIVERS\mausbcv.sys --> d:\windows\system32\DRIVERS\mausbcv.sys [?]
S3 sdAuxService;PC Tools Auxiliary Service;d:\program files\Spyware Doctor\pctsAuxs.exe [8/26/2009 11:20 AM 356920]
--- Other Services/Drivers In Memory ---
*Deregistered* - wdyafakj
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://mail.google.com/mail/?ui=1
Trusted Zone: beatport.com\www
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-29 09:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-08-29 10:00
ComboFix-quarantined-files.txt 2009-08-29 16:00
ComboFix2.txt 2009-08-29 13:08
ComboFix3.txt 2008-07-14 07:17
ComboFix4.txt 2008-06-28 14:51
ComboFix5.txt 2009-08-29 15:55
Pre-Run: 28,108,300,288 bytes free
Post-Run: 28,096,512,000 bytes free
131 --- E O F --- 2007-12-21 18:18
I'm running the ksper scanner and did it wrong the first time it wouldnt save out the log..anways it said it found two threats...i'll post the findings when the scan is done