Below is the DDS and i have attached the second list in a compressed folder. Originaly Spybot detected Win32. I deleted windows xp pro and reinstalled it with the disk. When i downloaded spybot and opened it immedietly detected win32.downloader.dequ. I'm wondering if this is the same infection? Is this spyware?
Thanks
DDS (Ver_09-12-01.01) - NTFSx86
Run by Administrator at 7:47:04.23 on 24/12/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.254.29 [GMT 0:00]
AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WUSB54GSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\osk.exe
C:\WINDOWS\system32\MSSWCHX.EXE
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Temporary Directory 4 for RootkitRevealer.zip\RootkitRevealer.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\HUYFIV.exe
C:\Documents and Settings\Administrator\My Documents\Downloads\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.co.uk/
uSearch Bar = hxxp://www.yahoo.com/search/ie.html
uInternet Connection Wizard,ShellNext = iexplore
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Hosts: 127.0.0.1
www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\7il91260.default\
FF - prefs.js: keyword.URL - hxxp://uk.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_uk&p=
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 142832]
=============== Created Last 30 ================
2009-12-24 07:19:51 3989504 ----a-w- c:\windows\system32\PGIVUD
2009-12-24 04:55:21 17801 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-12-24 04:55:18 17992 ----a-w- c:\windows\system32\bcm42rly.sys
2009-12-24 04:54:51 0 d-----w- c:\program files\Compact Wireless-G USB Network Adapter with SpeedBooster
2009-12-24 04:54:46 609 ----a-w- c:\windows\system32\WLAN.INI
2009-12-22 07:58:58 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-12-22 07:58:58 215920 ----a-w- c:\windows\system32\muweb.dll
2009-12-22 07:58:58 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
2009-12-18 03:30:18 6400 -c--a-w- c:\windows\system32\dllcache\splitter.sys
2009-12-18 03:30:18 6400 ----a-w- c:\windows\system32\drivers\splitter.sys
2009-12-18 03:30:11 82944 -c--a-w- c:\windows\system32\dllcache\wdmaud.sys
2009-12-18 03:30:11 82944 ----a-w- c:\windows\system32\drivers\wdmaud.sys
2009-12-18 03:30:06 52864 -c--a-w- c:\windows\system32\dllcache\dmusic.sys
2009-12-18 03:30:06 52864 ----a-w- c:\windows\system32\drivers\DMusic.sys
2009-12-18 03:29:57 54272 -c--a-w- c:\windows\system32\dllcache\swmidi.sys
2009-12-18 03:29:57 54272 ----a-w- c:\windows\system32\drivers\swmidi.sys
2009-12-18 03:29:47 142464 -c--a-w- c:\windows\system32\dllcache\aec.sys
2009-12-18 03:29:47 142464 ----a-w- c:\windows\system32\drivers\aec.sys
2009-12-18 03:29:37 171776 -c--a-w- c:\windows\system32\dllcache\kmixer.sys
2009-12-18 03:29:37 171776 ----a-w- c:\windows\system32\drivers\kmixer.sys
2009-12-18 03:29:26 2944 -c--a-w- c:\windows\system32\dllcache\drmkaud.sys
2009-12-18 03:29:26 2944 ----a-w- c:\windows\system32\drivers\drmkaud.sys
2009-12-18 03:29:18 60800 -c--a-w- c:\windows\system32\dllcache\sysaudio.sys
2009-12-18 03:29:18 60800 ----a-w- c:\windows\system32\drivers\sysaudio.sys
2009-12-18 03:29:01 7552 -c--a-w- c:\windows\system32\dllcache\mskssrv.sys
2009-12-18 03:29:01 7552 ----a-w- c:\windows\system32\drivers\MSKSSRV.sys
2009-12-18 03:28:45 4992 -c--a-w- c:\windows\system32\dllcache\mspqm.sys
2009-12-18 03:28:45 4992 ----a-w- c:\windows\system32\drivers\MSPQM.sys
2009-12-18 03:27:52 5376 -c--a-w- c:\windows\system32\dllcache\mspclock.sys
2009-12-18 03:27:52 5376 ----a-w- c:\windows\system32\drivers\MSPCLOCK.sys
2009-12-18 03:26:04 145792 -c--a-w- c:\windows\system32\dllcache\portcls.sys
2009-12-18 03:26:04 145792 ----a-w- c:\windows\system32\drivers\portcls.sys
2009-12-18 03:26:02 4096 -c--a-w- c:\windows\system32\dllcache\ksuser.dll
2009-12-18 03:26:02 4096 ----a-w- c:\windows\system32\ksuser.dll
2009-12-18 03:26:01 60288 -c--a-w- c:\windows\system32\dllcache\drmk.sys
2009-12-18 03:26:01 60288 ----a-w- c:\windows\system32\drivers\drmk.sys
2009-12-18 03:25:53 130048 -c--a-w- c:\windows\system32\dllcache\ksproxy.ax
2009-12-18 03:25:53 130048 ----a-w- c:\windows\system32\ksproxy.ax
2009-12-18 03:24:54 4816 ----a-w- c:\windows\system32\drivers\aeaudio.sys
2009-12-18 03:24:53 3744 ----a-w- c:\windows\system32\drivers\smsens.sys
2009-12-18 03:24:40 765952 ----a-w- c:\windows\system\crlds3d.dll
2009-12-18 03:24:37 0 d-----w- c:\windows\VirtualEar
2009-12-18 03:24:36 720896 ----a-w- c:\windows\system32\Audio3d.dll
2009-12-18 03:24:31 991232 ----a-w- c:\windows\system32\virtear.dll
2009-12-18 03:24:17 612352 ----a-w- c:\windows\system32\drivers\smwdm.sys
2009-12-18 03:24:15 720896 -c--a-w- c:\windows\system32\dllcache\a3d.dll
2009-12-18 03:24:15 720896 ----a-w- c:\windows\system32\a3d.dll
2009-12-18 03:23:55 0 d-----w- c:\program files\Analog Devices
2009-12-18 03:23:38 45056 ----a-w- c:\windows\system32\CleanUp.exe
2009-12-18 03:22:45 49152 ----a-w- c:\windows\system32\DSndUp.exe
2009-12-18 03:20:30 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-12-18 03:04:59 0 d-----w- C:\dell
2009-12-18 02:27:26 0 d-----w- c:\program files\Trend Micro
2009-12-18 01:03:30 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-12-18 00:56:26 0 d-s---w- c:\documents and settings\administrator\UserData
2009-12-18 00:55:44 0 d-----w- c:\program files\Microsoft Security Essentials
2009-12-18 00:51:47 0 d-----w- c:\program files\Spybot - Search & Destroy
2009-12-18 00:51:47 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-12-18 00:38:20 0 d-----w- c:\docume~1\admini~1\applic~1\AVG8
2009-12-18 00:36:43 0 d-----w- c:\windows\system32\PreInstall
2009-12-18 00:34:35 135168 -c----w- c:\windows\system32\dllcache\shsvcs.dll
2009-12-18 00:32:02 0 d--h--w- c:\windows\$hf_mig$
2009-12-18 00:32:00 332288 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-12-18 00:30:41 0 d-----w- c:\windows\system32\SoftwareDistribution
2009-12-15 23:11:52 0 d-----w- c:\windows\system32\wbem\AutoRecover
2009-12-15 22:17:21 0 d-sh--w- c:\documents and settings\all users\DRM
2009-12-15 22:15:56 0 d-----w- c:\program files\common files\MSSoap
2009-12-15 22:14:42 0 d--h--w- c:\program files\WindowsUpdate
2009-12-15 22:14:42 0 d-----w- c:\program files\Online Services
2009-12-15 22:14:32 0 d-----w- c:\program files\Messenger
2009-12-15 22:14:27 0 d-----w- c:\program files\MSN Gaming Zone
2009-12-15 22:13:53 0 d-----w- c:\program files\Windows NT
2009-12-15 22:06:13 0 d-----w- c:\program files\common files\ODBC
2009-12-15 22:06:09 0 d-----w- c:\program files\common files\SpeechEngines
2009-12-15 22:05:46 0 d-----r- c:\documents and settings\all users\Documents
==================== Find3M ====================
2009-12-15 22:15:03 21640 ----a-w- c:\windows\system32\emptyregdb.dat
============= FINISH: 7:49:07.56 ===============