Hi Blade. Good news - thanks to your help, those error messages at startup are now gone. Ran through those programs you suggested and the logs are attached below.
I have also read the article regarding p2p. Bittorrent was installed before but it was already uninstalled from my computer prior to the error messages happening. Perhaps it wasn't fast enough to avoid the Virtumonde infection. D:\Bit Torrent only contained the installation file from last time which I have now removed along with the folder. Could not locate C:\Program Files\DNA.
Other than that, everything seems to be running fine. Does that mean my computer is back to being infection-free again?
____________________________
Combofix
ComboFix 08-09-24.08 - Edmond 2008-09-25 10:50:31.2 - NTFSx86
Running from: C:\Users\Edmond\Desktop\ComboFix.exe
Command switches used :: C:\Users\Edmond\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-08-25 to 2008-09-25 )))))))))))))))))))))))))))))))
.
2008-09-25 10:49 . 2008-09-25 10:49 <DIR> d-------- C:\32788R22FWJFW
2008-09-21 22:40 . 2008-09-21 22:40 <DIR> d--h----- C:\Users\All Users\CanonBJ
2008-09-21 22:40 . 2008-09-21 22:40 <DIR> d--h----- C:\ProgramData\CanonBJ
2008-09-21 13:05 . 2008-09-21 13:05 <DIR> d-------- C:\Users\Edmond\AppData\Roaming\Talkback
2008-09-21 13:05 . 2008-09-21 13:05 0 --a------ C:\Windows\nsreg.dat
2008-09-21 13:04 . 2008-09-21 13:04 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-09-21 13:04 . 2008-09-21 13:04 <DIR> d-------- C:\Program Files\Common Files\Real
2008-09-21 13:04 . 2008-09-21 13:04 499,712 --a------ C:\Windows\System32\msvcp71.dll
2008-09-21 13:04 . 2008-09-21 13:04 348,160 --a------ C:\Windows\System32\msvcr71.dll
2008-09-20 17:29 . 2008-09-20 17:29 130,208 -r------- C:\Windows\bwUnin-8.1.1.87-8876480SL.exe
2008-09-20 14:12 . 2008-09-20 14:12 <DIR> d-------- C:\Users\Edmond\AppData\Roaming\Logitech
2008-09-20 14:12 . 2008-09-20 14:12 127,034 -r------- C:\Windows\bwUnin-8.1.1.50-8876480SL.exe
2008-09-20 14:11 . 2008-09-20 14:11 0 --ah----- C:\Windows\System32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-09-20 14:10 . 2007-04-23 04:00 163,840 --a------ C:\Windows\System32\kemutb.dll
2008-09-20 14:10 . 2007-04-23 04:00 135,168 --a------ C:\Windows\System32\KemUtil.dll
2008-09-20 14:10 . 2007-04-23 04:00 110,592 --a------ C:\Windows\System32\KemWnd.dll
2008-09-20 14:10 . 2007-04-23 04:00 69,632 --a------ C:\Windows\System32\KemXML.dll
2008-09-20 14:10 . 2008-09-20 14:10 0 --ah----- C:\Windows\System32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2008-09-20 14:09 . 2008-09-20 14:09 <DIR> d-------- C:\Users\Edmond\AppData\Roaming\InstallShield
2008-09-20 14:09 . 2008-09-20 14:09 <DIR> d-------- C:\Users\All Users\Logitech
2008-09-20 14:09 . 2008-09-20 14:09 <DIR> d-------- C:\ProgramData\Logitech
2008-09-20 14:09 . 2008-09-20 14:10 <DIR> d-------- C:\Program Files\Common Files\Logitech
2008-09-20 14:06 . 2008-09-20 14:06 <DIR> d-------- C:\Users\All Users\LogiShrd
2008-09-20 14:06 . 2008-09-20 14:06 <DIR> d-------- C:\ProgramData\LogiShrd
2008-09-20 10:45 . 2008-07-19 15:09 1,811,656 --a------ C:\Windows\System32\wuaueng.dll
2008-09-20 10:45 . 2008-07-19 13:44 1,524,736 --a------ C:\Windows\System32\wucltux.dll
2008-09-20 10:45 . 2008-07-19 15:09 563,912 --a------ C:\Windows\System32\wuapi.dll
2008-09-20 10:45 . 2008-07-18 22:08 163,904 --a------ C:\Windows\System32\wuwebv.dll
2008-09-20 10:45 . 2008-07-19 13:44 83,456 --a------ C:\Windows\System32\wudriver.dll
2008-09-20 10:45 . 2008-07-19 15:10 53,448 --a------ C:\Windows\System32\wuauclt.exe
2008-09-20 10:45 . 2008-07-19 15:10 45,768 --a------ C:\Windows\System32\wups2.dll
2008-09-20 10:45 . 2008-07-19 15:10 36,552 --a------ C:\Windows\System32\wups.dll
2008-09-20 10:45 . 2008-07-18 20:44 31,232 --a------ C:\Windows\System32\wuapp.exe
2008-09-18 12:44 . 2008-09-18 12:44 <DIR> d-------- C:\Program Files\Xvid
2008-09-18 12:44 . 2008-04-27 10:33 765,952 --a------ C:\Windows\System32\xvidcore.dll
2008-09-18 12:44 . 2008-04-27 10:35 180,224 --a------ C:\Windows\System32\xvidvfw.dll
2008-09-18 12:44 . 2007-06-28 18:55 77,824 --a------ C:\Windows\System32\xvid.ax
2008-09-17 21:55 . 2008-09-17 21:55 <DIR> d-------- C:\PerfLogs
2008-09-17 18:59 . 2008-01-19 17:33 8,139,264 --a------ C:\Windows\System32\ssBranded.scr
2008-09-17 18:58 . 2008-01-19 17:35 3,072,000 --a------ C:\Windows\System32\networkmap.dll
2008-09-17 18:57 . 2008-01-19 17:36 2,588,160 --a------ C:\Windows\System32\UIHub.dll
2008-09-17 18:56 . 2008-01-19 17:32 5,714,432 --a------ C:\Windows\System32\logon.scr
2008-09-17 18:55 . 2008-01-19 16:06 8,147,456 --a------ C:\Windows\System32\wmploc.DLL
2008-09-17 18:53 . 2008-01-19 17:36 704,512 --a------ C:\Windows\System32\SmiEngine.dll
2008-09-17 18:53 . 2008-01-19 17:36 357,888 --a------ C:\Windows\System32\wbemcomn.dll
2008-09-17 18:53 . 2008-01-19 17:34 305,152 --a------ C:\Windows\System32\msdelta.dll
2008-09-17 18:53 . 2008-01-19 17:34 258,560 --a------ C:\Windows\System32\dpx.dll
2008-09-17 18:53 . 2008-01-19 17:34 246,784 --a------ C:\Windows\System32\drvstore.dll
2008-09-17 18:53 . 2008-01-19 17:36 218,624 --a------ C:\Windows\System32\wdscore.dll
2008-09-17 18:53 . 2008-01-19 17:36 139,264 --a------ C:\Windows\System32\SmiInstaller.dll
2008-09-17 18:53 . 2008-01-19 17:33 130,560 --a------ C:\Windows\System32\PkgMgr.exe
2008-09-17 18:53 . 2008-01-19 17:35 35,328 --a------ C:\Windows\System32\mspatcha.dll
2008-09-13 17:50 . 2008-09-13 17:50 <DIR> d-------- C:\Users\All Users\Apple
2008-09-13 17:50 . 2008-09-13 17:50 <DIR> d-------- C:\ProgramData\Apple
2008-09-13 17:50 . 2008-09-13 17:50 <DIR> d-------- C:\Program Files\Apple Software Update
2008-09-13 17:49 . 2008-09-13 17:49 <DIR> d-------- C:\Users\All Users\Apple Computer
2008-09-13 17:49 . 2008-09-13 17:49 <DIR> d-------- C:\ProgramData\Apple Computer
2008-09-13 17:49 . 2008-09-13 17:49 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-09-12 23:26 . 2008-09-13 08:17 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-09-12 23:26 . 2008-09-13 08:17 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-09-11 21:26 . 2008-09-25 00:48 <DIR> d-------- C:\Users\Edmond\AppData\Roaming\Hamachi
2008-09-11 21:25 . 2008-09-11 21:25 25,280 --a------ C:\Windows\System32\drivers\hamachi.sys
2008-09-11 18:58 . 2008-09-17 22:40 <DIR> d-------- C:\Users\All Users\NVIDIA
2008-09-11 18:58 . 2008-09-17 22:40 <DIR> d-------- C:\ProgramData\NVIDIA
2008-09-10 13:58 . 2008-07-31 11:13 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-09-10 13:58 . 2008-07-31 13:32 28,160 --a------ C:\Windows\System32\Apphlpdm.dll
2008-09-10 13:57 . 2008-06-26 13:29 303,616 --a------ C:\Windows\System32\wmpeffects.dll
2008-09-10 04:48 . 2008-09-09 10:52 <DIR> d-------- C:\Windows\Panther
2008-09-10 04:47 . 2008-09-10 04:47 <DIR> d-------- C:\Windows\System32\OEM
2008-09-10 04:47 . 2008-09-17 22:03 <DIR> d--hs---- C:\Boot
2008-09-10 04:47 . 2008-01-19 17:45 333,203 -rahs---- C:\bootmgr
2008-09-10 04:47 . 2008-09-10 04:47 8,192 -ra-s---- C:\BOOTSECT.BAK
2008-09-10 04:47 . 2007-02-22 05:56 36 -rah----- C:\Windows\DELL_VERSION
2008-09-09 23:57 . 2008-09-09 23:57 269,312 --a------ C:\Windows\System32\es.dll
2008-09-09 23:30 . 2008-09-09 23:30 <DIR> d-------- C:\Users\Edmond\AppData\Roaming\DAEMON Tools
2008-09-09 23:30 . 2008-09-09 23:30 717,296 --a------ C:\Windows\System32\drivers\sptd.sys
2008-09-09 23:25 . 2008-09-09 23:26 <DIR> d-------- C:\Users\Edmond\AppData\Roaming\Roxio
2008-09-09 20:32 . 2008-09-09 20:32 376 --a------ C:\Windows\ODBC.INI
2008-09-09 20:31 . 2007-04-09 13:23 28,040 --a------ C:\Windows\System32\mdimon.dll
2008-09-09 20:28 . 2008-09-09 20:28 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-09-09 20:27 . 2008-09-09 20:27 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-09-09 20:26 . 2008-09-11 17:02 <DIR> d-------- C:\Program Files\Microsoft Works
2008-09-09 20:25 . 2008-09-09 20:25 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-09-09 16:36 . 2008-09-09 16:36 <DIR> d-------- C:\Windows\PCHEALTH
2008-09-09 16:27 . 2008-09-09 16:28 <DIR> d-------- C:\Users\All Users\OrbNetworks
2008-09-09 16:27 . 2008-09-09 16:28 <DIR> d-------- C:\ProgramData\OrbNetworks
2008-09-09 16:27 . 2008-09-09 16:27 <DIR> d-------- C:\Program Files\Winamp Remote
2008-09-09 16:26 . 2008-09-09 16:29 <DIR> d-------- C:\Users\Edmond\AppData\Roaming\Winamp
2008-09-09 16:26 . 2008-09-09 16:28 <DIR> d-------- C:\Program Files\Winamp
2008-09-09 15:44 . 2008-09-09 15:44 <DIR> d-------- C:\Users\All Users\SupportSoft
2008-09-09 15:44 . 2008-09-09 15:44 <DIR> d-------- C:\ProgramData\SupportSoft
2008-09-09 15:44 . 2008-09-09 15:44 <DIR> d-------- C:\Program Files\Dell Support Center
2008-09-09 15:44 . 2008-09-09 15:44 <DIR> d-------- C:\Program Files\Common Files\supportsoft
2008-09-09 13:59 . 2008-09-09 15:39 <DIR> d-------- C:\Windows\System32\DLA
2008-09-09 13:59 . 2006-07-21 11:21 99,176 --a------ C:\Windows\System32\drivers\DRVMCDB.SYS
2008-09-09 13:59 . 2006-10-26 16:21 92,920 --a------ C:\Windows\DLA.EXE
2008-09-09 13:59 . 2006-10-26 16:21 56,056 --a------ C:\Windows\System32\DLAAPI_W.DLL
2008-09-09 13:59 . 2007-02-09 12:34 51,768 --a------ C:\Windows\System32\drivers\DRVNDDM.SYS
2008-09-09 13:59 . 2007-02-08 20:05 28,120 --a------ C:\Windows\System32\drivers\DLARTL_M.SYS
2008-09-09 13:59 . 2007-02-08 20:05 12,856 --a------ C:\Windows\System32\drivers\DLACDBHM.SYS
2008-09-09 13:59 . 2008-09-18 11:30 562 --a------ C:\Windows\wininit.ini
2008-09-09 13:58 . 2008-09-09 13:58 <DIR> d-------- C:\Users\All Users\Sonic
2008-09-09 13:58 . 2008-09-09 13:58 <DIR> d-------- C:\ProgramData\Sonic
2008-09-09 13:57 . 2008-09-09 13:59 <DIR> d-------- C:\Users\All Users\Roxio
2008-09-09 13:57 . 2008-09-09 13:59 <DIR> d-------- C:\ProgramData\Roxio
2008-09-09 13:56 . 2008-09-09 13:56 <DIR> d-------- C:\Program Files\Roxio
2008-09-09 13:56 . 2008-09-09 13:56 <DIR> d-------- C:\Program Files\Common Files\SureThing Shared
2008-09-09 13:55 . 2008-09-09 13:55 <DIR> d-------- C:\Users\All Users\InstallShield
2008-09-09 13:55 . 2008-09-09 13:55 <DIR> d-------- C:\ProgramData\InstallShield
2008-09-09 13:55 . 2008-09-09 13:59 <DIR> d-------- C:\Program Files\Common Files\Sonic Shared
2008-09-09 13:55 . 2008-09-09 13:55 <DIR> d-------- C:\Program Files\Common Files\Roxio Shared
2008-09-09 13:43 . 2008-09-09 13:43 361,984 --a------ C:\Windows\System32\IPSECSVC.DLL
2008-09-09 13:43 . 2008-09-09 13:43 272,896 --a------ C:\Windows\System32\polstore.dll
2008-09-09 13:43 . 2008-09-09 13:43 61,440 --a------ C:\Windows\System32\winipsec.dll
2008-09-09 13:43 . 2008-09-09 13:43 28,672 --a------ C:\Windows\System32\FwRemoteSvr.dll
2008-09-09 13:42 . 2008-09-09 16:30 <DIR> d-------- C:\Users\All Users\WLInstaller
2008-09-09 13:42 . 2008-09-09 16:30 <DIR> d-------- C:\ProgramData\WLInstaller
2008-09-09 13:42 . 2008-09-09 16:36 <DIR> d-------- C:\Program Files\Windows Live
2008-09-09 13:42 . 2008-09-09 14:07 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-09-09 13:42 . 2008-09-09 13:42 1,820 --a------ C:\Windows\System32\rasctrnm.h
2008-09-09 13:36 . 2008-09-09 13:36 2,048 --a------ C:\Windows\System32\tzres.dll
2008-09-09 13:28 . 2008-09-09 13:28 9,847,296 --a------ C:\Windows\System32\NlsData000a.dll
2008-09-09 13:27 . 2008-09-09 13:27 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-09-09 13:27 . 2008-09-09 13:27 827,392 --a------ C:\Windows\System32\wininet.dll
2008-09-09 13:25 . 2008-09-09 13:25 988,216 --a------ C:\Windows\System32\winload.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-17 12:03 174 --sha-w C:\Program Files\desktop.ini
2008-09-17 11:57 --------- d-----w C:\Program Files\Windows Sidebar
2008-09-17 11:57 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-09-17 11:57 --------- d-----w C:\Program Files\Windows Mail
2008-09-17 11:57 --------- d-----w C:\Program Files\Windows Journal
2008-09-17 11:57 --------- d-----w C:\Program Files\Windows Defender
2008-09-17 11:57 --------- d-----w C:\Program Files\Windows Collaboration
2008-09-17 11:57 --------- d-----w C:\Program Files\Windows Calendar
2008-09-17 09:20 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-09-17 09:20 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-09-09 03:28 801,280 ----a-w C:\Windows\System32\NaturalLanguage6.dll
2008-09-09 03:19 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-08-02 03:26 36,864 ----a-w C:\Windows\System32\cdd.dll
2008-08-02 01:01 625,152 ----a-w C:\Windows\system32\drivers\dxgkrnl.sys
2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-06-26 03:29 565,248 ----a-w C:\Windows\System32\emdmgmt.dll
2008-06-26 03:29 45,056 ----a-w C:\Windows\System32\dataclen.dll
.
((((((((((((((((((((((((((((( snapshot@2008-09-25_ 1.25.25.95 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-24 14:59:27 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-09-24 23:47:50 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-09-24 14:59:27 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-09-24 23:47:50 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-09-24 15:01:06 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-09-24 23:48:47 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-09-24 15:01:01 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-09-24 23:49:24 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-09-24 23:49:24 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-09-24 15:01:52 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-09-24 23:50:10 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-09-24 15:01:52 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-24 23:50:10 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-09-24 15:01:52 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-09-24 23:50:10 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-09-24 11:27:59 4,598 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\dotastrategy.com\dotastrategy.com\Data.dat
+ 2008-09-24 15:44:12 4,598 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\dotastrategy.com\dotastrategy.com\Data.dat
- 2008-09-24 14:11:13 4,786 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\google.com.au\google.com.au\Data.dat
+ 2008-09-25 00:43:24 4,786 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\google.com.au\google.com.au\Data.dat
+ 2008-09-24 15:38:32 4,716 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\mozilla.com\mozilla.com\Data.dat
- 2008-09-24 15:23:05 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-09-25 00:50:24 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-09-25 00:50:24 262,144 ---ha-w C:\Windows\System32\config\systemprofile\ntuser.dat.LOG1
- 2008-09-24 15:04:03 101,052 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-09-24 23:54:11 101,052 ----a-w C:\Windows\System32\perfc009.dat
- 2008-09-24 15:04:03 586,980 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-09-24 23:54:11 586,980 ----a-w C:\Windows\System32\perfh009.dat
- 2008-09-24 15:01:26 4,890 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-853690081-164624546-737061790-1000_UserData.bin
+ 2008-09-24 23:49:44 4,930 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-853690081-164624546-737061790-1000_UserData.bin
- 2008-09-24 15:01:25 49,436 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-09-24 23:49:44 49,544 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-09-24 15:01:24 29,094 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-09-24 23:49:43 29,426 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2008-04-01 507904]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 202544]
"DAEMON Tools Lite"="D:\Daemon Tools\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-08-04 36352]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 202544]
"QuickTime Task"="D:\Quicktime\QTTask.exe" [2008-09-06 413696]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-17 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-17 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-17 81920]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-09-21 185896]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 C:\Windows\RtHDVCpl.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 C:\Windows\KHALMNPR.Exe]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - D:\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-09-20 91440]
Logitech SetPoint.lnk - D:\Logitech\SetPoint\SetPoint.exe [2008-09-20 692224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{F1A12D9F-C56D-450E-8723-050A10594274}"= Profile=Private|Profile=Public|C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{5BBD299D-A2D5-48B6-B7A5-F3312507972F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{18A60570-58D4-4EAE-9484-08CA5421C17F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{6F21EC25-ADE9-477F-A62C-D0BF0DCDFF6B}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{D0CC8678-F3F9-4B6F-BD7A-82BE4E167AC7}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{DBF00D31-6F87-4C4F-8263-DB3828F6D486}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{1E1D0F8D-19A9-4815-88DE-83E6C80BAF9F}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{0CB98F1B-FDF7-413D-9925-10B94BB6F34C}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{B943EA31-D6A5-4CB4-A03B-B372D1B23E28}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{4150C131-390E-4AE3-A606-971F62C0C4A0}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{B91AF141-6B06-4224-AA50-1EA6F50F3863}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{536ACCAF-11FF-4C7D-95FD-B040CF4A55FD}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{FC129E5D-A44D-4712-B97C-BE8983A04B47}"= UDP

:\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{3A4F8897-74CE-4604-8DEE-01D290775C66}"= TCP

:\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{8C4850A9-9A14-4001-941E-FBBC37B3E5BA}"= UDP

:\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{6CD919D5-8654-46CE-AF27-0D5D7B36503B}"= TCP

:\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{56C75ED7-25D8-4279-8DD2-600146A0D8E5}"= UDP

:\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{CE55C8C1-C8E5-4867-9D37-1727B3F0B87F}"= TCP

:\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 28120]
R2 AERTFilters;Andrea RT Filters Service;C:\Windows\system32\AERTSrv.exe [2007-12-05 77824]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-07-23 206112]
R3 VST_DPV;VST_DPV;C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648]
R3 VSTHWBS2;VSTHWBS2;C:\Windows\system32\DRIVERS\VSTBS23.SYS [2006-11-02 251904]
.
Contents of the 'Scheduled Tasks' folder
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-25 10:52:11
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\Windows\Explorer.exe
-> C:\Program Files\McAfee\SiteAdvisor\saHook.dll
.
Completion time: 2008-09-25 10:53:37
ComboFix-quarantined-files.txt 2008-09-25 00:53:34
ComboFix2.txt 2008-09-24 15:26:38
Pre-Run: 30,717,308,928 bytes free
Post-Run: 30,580,584,448 bytes free
278 --- E O F --- 2008-09-21 00:19:41
____________________________
EOS
# version=4
# OnlineScanner.ocx=1.0.0.56
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3469 (20080924)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=05f4ccd19ab10b4ca3c64966ef8cfd2e
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2008-09-25 01:31:30
# local_time=2008-09-25 11:31:30 (+1000, AUS Eastern Standard Time)
# country="Australia"
# osver=6.0.6001 NT Service Pack 1
# scanned=381074
# found=13
# scan_time=1697
D:\My folder\Emoticons\Display Pics\Extract.exe Win32/Adware.180Solutions application (deleted) 00000000000000000000000000000000
D:\My folder\Emoticons\Display Pics\Extract.exe ?NSIS ?msbb.exe Win32/Adware.180Solutions application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
D:\My folder\Emoticons\Display Pics\Install.exe Win32/Adware.180Solutions application (deleted) 00000000000000000000000000000000
D:\My folder\Emoticons\Display Pics\Install.exe ?NSIS ?saap.exe Win32/Adware.180Solutions application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
D:\My folder\Emoticons\Display Pics\MSN-EMOTIONS-DP.zip Win32/Adware.180Solutions application (deleted) 00000000000000000000000000000000
D:\My folder\Emoticons\Display Pics\MSN-EMOTIONS-DP.zip ?ZIP ?Install.exe Win32/Adware.180Solutions application (error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
D:\My folder\Emoticons\Display Pics\MSN-EMOTIONS-DP.zip ?ZIP ?Install.exe ?NSIS ?saap.exe Win32/Adware.180Solutions application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
D:\My folder\Emoticons\Display Pics\MSN-Mood2-Diplsay-Pictures.zip Win32/Adware.180Solutions application (deleted) 00000000000000000000000000000000
D:\My folder\Emoticons\Display Pics\MSN-Mood2-Diplsay-Pictures.zip ?ZIP ?Install.exe Win32/Adware.180Solutions application (error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
D:\My folder\Emoticons\Display Pics\MSN-Mood2-Diplsay-Pictures.zip ?ZIP ?Install.exe ?NSIS ?saap.exe Win32/Adware.180Solutions application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
D:\My folder\Emoticons\Display Pics\MSN6.DP.Pack.Mood.zip Win32/Adware.180Solutions application (deleted) 00000000000000000000000000000000
D:\My folder\Emoticons\Display Pics\MSN6.DP.Pack.Mood.zip ?ZIP ?Extract.exe Win32/Adware.180Solutions application (error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
D:\My folder\Emoticons\Display Pics\MSN6.DP.Pack.Mood.zip ?ZIP ?Extract.exe ?NSIS ?msbb.exe Win32/Adware.180Solutions application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
____________________________
HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:27:50 PM, on 25/09/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
D:\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
D:\Logitech\SetPoint\SetPoint.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Windows\system32\wbem\unsecapp.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Windows\system32\conime.exe
C:\Windows\Explorer.exe
D:\Opera Browser\Opera 9.52\opera.exe
C:\Windows\system32\NOTEPAD.EXE
D:\Virus Cleaners\HijackThis.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "D:\Quicktime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Daemon Tools\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = D:\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\OFFICE~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\OFFICE~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Spybot\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Spybot\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O15 - ESC Trusted Zone:
http://*.update.microsoft.com
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) -
http://www.eset.eu/OnlineScanner.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - D:\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
--
End of file - 6232 bytes