Apologies if I should have attached this to one of the other thread. Here is a copy of the log.
ComboFix 08-04-09.9 - admin 2008-04-11 8:28:22.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.71 [GMT 1:00]
Running from: C:\Documents and Settings\admin\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\PC-Cleaner
C:\WINDOWS\fkdnrwsv.dll
C:\WINDOWS\stfngdvw.dll
C:\WINDOWS\svpekgongpv.dll
C:\WINDOWS\sxfnewqb.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-11 to 2008-04-11 )))))))))))))))))))))))))))))))
.
2008-04-10 14:25 . 2008-04-10 14:25 102,400 --a------ C:\WINDOWS\system32\lytypmpc.exe
2008-04-10 13:10 . 2008-04-10 13:10 175 --a------ C:\WINDOWS\wininit.ini
2008-04-10 12:06 . 2008-04-10 12:06 <DIR> d-------- C:\Program Files\FreeFixer
2008-04-10 11:28 . 2008-04-10 11:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-04-10 11:28 . 2008-04-10 11:47 <DIR> d-------- C:\Documents and Settings\admin\Application Data\Simply Super Software
2008-04-10 11:28 . 2006-05-25 15:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-04-10 11:28 . 2003-02-02 20:06 153,088 --a------ C:\WINDOWS\system32\unrar3.dll
2008-04-10 11:28 . 2005-08-26 01:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-04-10 11:28 . 2002-03-06 01:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-04-10 11:28 . 2006-06-19 13:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-04-10 10:53 . 2008-04-10 14:47 <DIR> d-------- C:\Program Files\XoftSpySE
2008-04-10 10:52 . 2008-04-10 10:57 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-04-07 16:25 . 2008-04-07 16:30 4,216 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-07 16:24 . 2008-04-07 16:33 <DIR> d-------- C:\TEMP\SmitfraudFix
2008-04-07 16:24 . 2008-04-07 16:23 1,306,941 --a------ C:\TEMP\SmitfraudFix.exe
2008-04-07 15:25 . 2008-04-07 15:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-07 15:19 . 2008-02-15 16:10 21,364,592 --a------ C:\TEMP\aaw2007.exe
2008-04-07 12:22 . 2008-04-07 12:23 2,751,368 --a------ C:\TEMP\ccsetup206.exe
2008-04-07 12:16 . 2008-04-07 12:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-07 12:13 . 2007-07-07 19:06 12,413,440 --a------ C:\TEMP\avgas-setup-7.5.1.43.exe
2008-04-07 08:56 . 2008-04-07 08:56 98,304 --a------ C:\WINDOWS\system32\lszsbqtm.exe
2008-04-04 14:58 . 2008-04-04 14:49 691,545 --a------ C:\WINDOWS\unins000.exe
2008-04-04 14:58 . 2008-04-04 14:58 2,541 --a------ C:\WINDOWS\unins000.dat
2008-04-04 14:45 . 2008-04-10 12:06 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-04 14:45 . 2008-04-10 12:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-04 12:05 . 2008-04-04 12:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\rixunmdc
2008-04-04 12:05 . 2008-04-04 12:05 102,400 --a------ C:\WINDOWS\system32\xyhmdcjw.exe
2008-03-19 16:38 . 2008-04-02 15:13 <DIR> d-------- C:\Stock
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-10 15:30 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-04-10 10:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
1998-04-26 23:00 570,128 ----a-w C:\Program Files\Common Files\dao350.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"ysnegqur"="C:\WINDOWS\system32\lytypmpc.exe" [2008-04-10 14:25 102400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 13:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 13:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 13:00 455168]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-08-14 17:29 290816]
"CARPService"="carpserv.exe" [2003-05-21 15:35 4608 C:\WINDOWS\system32\carpserv.exe]
"Display Settings"="C:\Program Files\HPQ\Notebook Utilities\hptasks.exe" [2002-08-15 06:26 45056]
"QT4HPOT"="C:\Program Files\HPQ\One-Touch\OneTouch.EXE" [2003-01-31 04:53 106496]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2003-04-19 04:03 110592]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2003-04-19 03:57 610304]
"ATIModeChange"="Ati2mdxx.exe" [2002-08-15 23:18 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2002-08-26 18:08 90112]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2003-02-26 16:25 180316]
"RoxioEngineUtility"="C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 18:44 65536]
"RoxioDragToDisc"="C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-07-18 17:23 868352]
"Client Access Service"="C:\Program Files\IBM\Client Access\cwbsvstr.exe" [2002-08-01 05:20 20530]
"Client Access Help Update"="C:\Program Files\IBM\Client Access\cwbinhlp.exe" [2002-08-01 05:20 24626]
"Client Access Check Version"="C:\Program Files\IBM\Client Access\cwbckver.exe" [2002-08-01 05:20 45106]
"Client Access Express Welcome"="C:\Program Files\IBM\Client Access\cwbwlwiz.exe" [2002-08-01 05:20 20480]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-02-29 16:44 66680]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-03-12 15:18 124128]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"WqyKBxJPTB"= C:\Documents and Settings\All Users\Application Data\rixunmdc\tunglmjq.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys [2001-08-17 13:12]
S3 ALiIRDA;ALi Infrared Device Driver;C:\WINDOWS\system32\DRIVERS\aliirda.sys [2001-12-17 23:54]
S3 CALIAUD;Conexant AMC 3D ENVIRONMENTAL AUDIO;C:\WINDOWS\system32\drivers\caliaud.sys [2002-11-05 16:04]
S3 CALIHALA;CALIHALA;C:\WINDOWS\system32\drivers\calihal.sys [2002-11-05 16:04]
S3 DCamUSBSTK017;STK017 Camera;C:\WINDOWS\system32\DRIVERS\STK017W2.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##mis006#e]
\Shell\AutoRun\command - V:\setup.EXE /AUTORUN
\Shell\configure\command - V:\setup.EXE
\Shell\install\command - V:\setup.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\menu.exe
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-11 08:30:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
MMTray = C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe????????4h????\??????|???????|X??|???????|n??|???????????????????|??W???????????????????????B???W?????????????????????,????SQ?????8????BG???4h|?X??????DY?????????????D?????Q?????P???+9G???????????Q????
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????7?8?4?7??????? ??3B?????????????T?B? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\tsd32.dll
.
Completion time: 2008-04-11 8:31:50
ComboFix-quarantined-files.txt 2008-04-11 07:31:33
Pre-Run: 33,704,665,088 bytes free
Post-Run: 33,753,174,016 bytes free
.
2008-04-10 10:07:19 --- E O F ---
ComboFix 08-04-09.9 - admin 2008-04-11 8:28:22.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.71 [GMT 1:00]
Running from: C:\Documents and Settings\admin\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\PC-Cleaner
C:\WINDOWS\fkdnrwsv.dll
C:\WINDOWS\stfngdvw.dll
C:\WINDOWS\svpekgongpv.dll
C:\WINDOWS\sxfnewqb.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-11 to 2008-04-11 )))))))))))))))))))))))))))))))
.
2008-04-10 14:25 . 2008-04-10 14:25 102,400 --a------ C:\WINDOWS\system32\lytypmpc.exe
2008-04-10 13:10 . 2008-04-10 13:10 175 --a------ C:\WINDOWS\wininit.ini
2008-04-10 12:06 . 2008-04-10 12:06 <DIR> d-------- C:\Program Files\FreeFixer
2008-04-10 11:28 . 2008-04-10 11:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-04-10 11:28 . 2008-04-10 11:47 <DIR> d-------- C:\Documents and Settings\admin\Application Data\Simply Super Software
2008-04-10 11:28 . 2006-05-25 15:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-04-10 11:28 . 2003-02-02 20:06 153,088 --a------ C:\WINDOWS\system32\unrar3.dll
2008-04-10 11:28 . 2005-08-26 01:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-04-10 11:28 . 2002-03-06 01:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-04-10 11:28 . 2006-06-19 13:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-04-10 10:53 . 2008-04-10 14:47 <DIR> d-------- C:\Program Files\XoftSpySE
2008-04-10 10:52 . 2008-04-10 10:57 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-04-07 16:25 . 2008-04-07 16:30 4,216 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-07 16:24 . 2008-04-07 16:33 <DIR> d-------- C:\TEMP\SmitfraudFix
2008-04-07 16:24 . 2008-04-07 16:23 1,306,941 --a------ C:\TEMP\SmitfraudFix.exe
2008-04-07 15:25 . 2008-04-07 15:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-07 15:19 . 2008-02-15 16:10 21,364,592 --a------ C:\TEMP\aaw2007.exe
2008-04-07 12:22 . 2008-04-07 12:23 2,751,368 --a------ C:\TEMP\ccsetup206.exe
2008-04-07 12:16 . 2008-04-07 12:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-07 12:13 . 2007-07-07 19:06 12,413,440 --a------ C:\TEMP\avgas-setup-7.5.1.43.exe
2008-04-07 08:56 . 2008-04-07 08:56 98,304 --a------ C:\WINDOWS\system32\lszsbqtm.exe
2008-04-04 14:58 . 2008-04-04 14:49 691,545 --a------ C:\WINDOWS\unins000.exe
2008-04-04 14:58 . 2008-04-04 14:58 2,541 --a------ C:\WINDOWS\unins000.dat
2008-04-04 14:45 . 2008-04-10 12:06 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-04 14:45 . 2008-04-10 12:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-04 12:05 . 2008-04-04 12:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\rixunmdc
2008-04-04 12:05 . 2008-04-04 12:05 102,400 --a------ C:\WINDOWS\system32\xyhmdcjw.exe
2008-03-19 16:38 . 2008-04-02 15:13 <DIR> d-------- C:\Stock
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-10 15:30 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-04-10 10:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
1998-04-26 23:00 570,128 ----a-w C:\Program Files\Common Files\dao350.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"ysnegqur"="C:\WINDOWS\system32\lytypmpc.exe" [2008-04-10 14:25 102400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 13:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 13:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 13:00 455168]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-08-14 17:29 290816]
"CARPService"="carpserv.exe" [2003-05-21 15:35 4608 C:\WINDOWS\system32\carpserv.exe]
"Display Settings"="C:\Program Files\HPQ\Notebook Utilities\hptasks.exe" [2002-08-15 06:26 45056]
"QT4HPOT"="C:\Program Files\HPQ\One-Touch\OneTouch.EXE" [2003-01-31 04:53 106496]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2003-04-19 04:03 110592]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2003-04-19 03:57 610304]
"ATIModeChange"="Ati2mdxx.exe" [2002-08-15 23:18 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2002-08-26 18:08 90112]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2003-02-26 16:25 180316]
"RoxioEngineUtility"="C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 18:44 65536]
"RoxioDragToDisc"="C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-07-18 17:23 868352]
"Client Access Service"="C:\Program Files\IBM\Client Access\cwbsvstr.exe" [2002-08-01 05:20 20530]
"Client Access Help Update"="C:\Program Files\IBM\Client Access\cwbinhlp.exe" [2002-08-01 05:20 24626]
"Client Access Check Version"="C:\Program Files\IBM\Client Access\cwbckver.exe" [2002-08-01 05:20 45106]
"Client Access Express Welcome"="C:\Program Files\IBM\Client Access\cwbwlwiz.exe" [2002-08-01 05:20 20480]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-02-29 16:44 66680]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-03-12 15:18 124128]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"WqyKBxJPTB"= C:\Documents and Settings\All Users\Application Data\rixunmdc\tunglmjq.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys [2001-08-17 13:12]
S3 ALiIRDA;ALi Infrared Device Driver;C:\WINDOWS\system32\DRIVERS\aliirda.sys [2001-12-17 23:54]
S3 CALIAUD;Conexant AMC 3D ENVIRONMENTAL AUDIO;C:\WINDOWS\system32\drivers\caliaud.sys [2002-11-05 16:04]
S3 CALIHALA;CALIHALA;C:\WINDOWS\system32\drivers\calihal.sys [2002-11-05 16:04]
S3 DCamUSBSTK017;STK017 Camera;C:\WINDOWS\system32\DRIVERS\STK017W2.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##mis006#e]
\Shell\AutoRun\command - V:\setup.EXE /AUTORUN
\Shell\configure\command - V:\setup.EXE
\Shell\install\command - V:\setup.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\menu.exe
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-11 08:30:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
MMTray = C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe????????4h????\??????|???????|X??|???????|n??|???????????????????|??W???????????????????????B???W?????????????????????,????SQ?????8????BG???4h|?X??????DY?????????????D?????Q?????P???+9G???????????Q????
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????7?8?4?7??????? ??3B?????????????T?B? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\tsd32.dll
.
Completion time: 2008-04-11 8:31:50
ComboFix-quarantined-files.txt 2008-04-11 07:31:33
Pre-Run: 33,704,665,088 bytes free
Post-Run: 33,753,174,016 bytes free
.
2008-04-10 10:07:19 --- E O F ---