Help - Search - Members - Calendar
Full Version: Virus Helppp
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
Gr3g
I have a critter running around on my hard drive somewhere. I've run numerous anti-virus programs but I can't seem to solve the problem. I can't change my folder options to show hidden files thats how I know I have a virus. I had Kavo on my computer maybe its that virus but i thought my anti-virus took care of it. I can't open my hard drives either when I click on them I have to go in the address bar and select them from a list for some reason.

Heres my hijack log

Scan saved at 4:40:08 PM, on 31/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
J:\Software\Lavasoft\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
J:\Software\AVG\avgamsvr.exe
J:\Software\AVG\avgupsvc.exe
J:\Software\KAV6\avp.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\LTMSG.exe
J:\Software\AVG\avgcc.exe
J:\Software\KAV6\avp.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
J:\Software\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [AVG7_CC] J:\Software\AVG\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVP] "J:\Software\KAV6\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [kava] C:\WINDOWS\system32\kavo.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] J:\Software\AVG\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Random House Webster's College Dictionary WordGenius Activate.LNK = C:\Program Files\WordGenius\WGRC.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1200974219031
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - J:\Software\Lavasoft\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - J:\Software\AVG\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - J:\Software\AVG\avgupsvc.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - J:\Software\KAV6\avp.exe

--
End of file - 4840 bytes

Thanks for your help in advance
LoPhatPhuud
Download Combofix from any of the links below, and save it to your desktop. For information regarding this download, please visit this webpage: http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Link 1
Link 2
Link 3


**Note: It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

--------------------------------------------------------------------

Double click on combofix.exe & follow the prompts.
    When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall
Gr3g
Okay here's what you requested LoPhatPhuud

ComboFix 08-02.03.1 - Greg 2008-02-03 15:15:26.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.217 [GMT -5:00]
Running from: C:\Documents and Settings\Greg\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
D:\Autorun.inf
I:\Autorun.inf
J:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 )))))))))))))))))))))))))))))))
.

2008-02-01 00:14 . 2008-02-01 00:14 <DIR> d-------- C:\Program Files\Canon
2008-02-01 00:11 . 2008-02-01 00:11 <DIR> d--h----- C:\CanonMF
2008-02-01 00:10 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-02-01 00:10 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-01-31 00:58 . 2008-01-31 00:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-31 00:54 . 2008-01-31 00:54 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-31 00:31 . 2008-01-31 00:31 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-01-30 00:09 . 2008-01-30 00:10 <DIR> d-------- C:\Dev-C++
2008-01-30 00:08 . 1996-07-18 13:06 297,472 --a------ C:\WINDOWS\uninst.exe
2008-01-29 23:13 . 2008-01-29 23:13 <DIR> d-------- C:\Documents and Settings\Greg\WINDOWS
2008-01-29 22:11 . 2008-01-29 22:11 <DIR> d-------- C:\Program Files\uTorrent
2008-01-29 22:11 . 2008-01-31 17:18 <DIR> d-------- C:\Documents and Settings\Greg\Application Data\uTorrent
2008-01-29 21:14 . 2008-01-31 22:13 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2008-01-25 13:35 . 2008-02-03 15:15 2,888,736 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-25 13:35 . 2008-02-01 16:06 45,452 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-25 13:35 . 2008-02-03 15:16 37,408 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-25 13:35 . 2008-02-01 16:06 6,356 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-25 13:32 . 2008-02-03 14:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-25 13:31 . 2008-01-25 13:31 <DIR> d-------- C:\KAV
2008-01-24 15:36 . 2008-01-24 15:37 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-01-22 22:23 . 2008-01-22 22:23 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-01-22 22:21 . 2004-09-09 21:30 57,344 --a------ C:\WINDOWS\system32\CNARLMNT.DLL
2008-01-22 22:21 . 2004-09-09 21:31 53,248 --a------ C:\WINDOWS\system32\cncilps1.dll
2008-01-22 22:21 . 2003-08-20 15:16 22,048 --a------ C:\WINDOWS\system32\cocpyinf.dll
2008-01-22 19:43 . 2008-01-22 19:43 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-22 19:43 . 2008-02-03 14:55 <DIR> d-------- C:\Documents and Settings\Greg\Application Data\AVG7
2008-01-22 19:43 . 2008-01-22 19:43 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-01-22 19:43 . 2008-01-22 19:43 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-01-22 19:42 . 2008-01-22 19:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-22 19:42 . 2008-01-22 19:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-01-22 19:30 . 2004-08-04 00:56 90,624 --a------ C:\WINDOWS\system32\kswdmcap.ax
2008-01-22 19:30 . 2004-08-04 00:56 90,624 --a--c--- C:\WINDOWS\system32\dllcache\kswdmcap.ax
2008-01-22 19:30 . 2004-08-04 00:56 61,952 --a------ C:\WINDOWS\system32\kstvtune.ax
2008-01-22 19:30 . 2004-08-04 00:56 61,952 --a--c--- C:\WINDOWS\system32\dllcache\kstvtune.ax
2008-01-22 19:30 . 2004-08-04 00:56 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2008-01-22 19:30 . 2004-08-04 00:56 53,760 --a--c--- C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2008-01-22 19:30 . 2004-08-04 00:56 43,008 --a------ C:\WINDOWS\system32\ksxbar.ax
2008-01-22 19:30 . 2004-08-04 00:56 43,008 --a--c--- C:\WINDOWS\system32\dllcache\ksxbar.ax
2008-01-22 19:30 . 2004-08-04 00:56 28,672 --a------ C:\WINDOWS\system32\vidcap.ax
2008-01-22 19:30 . 2004-08-04 00:56 28,672 --a--c--- C:\WINDOWS\system32\dllcache\vidcap.ax
2008-01-22 13:16 . 2008-01-22 13:16 <DIR> d-------- C:\Program Files\Microsoft Works
2008-01-22 13:15 . 2008-01-22 13:15 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-01-22 13:12 . 2008-01-22 13:16 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-01-22 13:11 . 2008-01-22 13:11 <DIR> dr-h----- C:\MSOCache
2008-01-22 13:11 . 2008-01-30 00:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-22 12:30 . 2008-01-22 12:30 <DIR> d-------- C:\Program Files\PowerISO
2008-01-22 12:28 . 2008-01-22 12:28 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-01-22 12:25 . 2008-01-22 12:25 <DIR> d-------- C:\Program Files\Instant CD & DVD Burner
2008-01-22 11:51 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-01-22 11:51 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-01-21 23:41 . 2008-01-21 23:41 268 --ah----- C:\sqmdata00.sqm
2008-01-21 23:41 . 2008-01-21 23:41 244 --ah----- C:\sqmnoopt00.sqm
2008-01-21 23:20 . 2008-01-21 23:20 <DIR> d-------- C:\Program Files\MSBuild
2008-01-21 23:17 . 2008-01-21 23:17 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-01-21 23:16 . 2008-01-21 23:16 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-01-21 23:15 . 2008-01-31 22:13 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-01-21 23:15 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-01-21 23:14 . 2008-01-21 23:14 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-01-21 23:14 . 2008-01-21 23:14 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-01-21 23:07 . 2008-01-21 23:08 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-01-21 23:04 . 2006-11-13 01:02 288,768 --------- C:\WINDOWS\system32\rhttpaa.dll
2008-01-21 23:04 . 2006-11-13 01:02 116,736 --------- C:\WINDOWS\system32\aaclient.dll
2008-01-21 23:04 . 2006-11-13 01:02 36,352 --------- C:\WINDOWS\system32\tsgqec.dll
2008-01-21 20:16 . 2008-01-31 22:14 <DIR> d-------- C:\Program Files\WordGenius
2008-01-21 20:16 . 2008-02-03 14:56 274 --a------ C:\WINDOWS\WGRC.INI
2008-01-21 20:14 . 2008-01-21 20:14 <DIR> d-------- C:\Documents and Settings\Greg\Contacts
2008-01-21 20:13 . 2008-01-21 20:13 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-01-21 20:11 . 2008-01-21 20:13 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-21 20:10 . 2008-01-21 20:13 <DIR> d-------- C:\Program Files\Windows Live
2008-01-21 20:10 . 2008-01-21 20:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-21 20:09 . 2008-01-21 20:09 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-01-21 11:31 . 2008-01-21 11:31 <DIR> d-------- C:\Program Files\VIA
2008-01-21 11:31 . 2005-03-09 11:17 11,692 --a------ C:\WINDOWS\system32\hg201hp.inf
2008-01-21 11:29 . 2004-09-20 15:20 16,121,856 --a------ C:\WINDOWS\system32\ALSNDMGR.CPL
2008-01-21 11:16 . 2008-01-22 11:57 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-01-21 11:16 . 2006-10-16 16:10 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-01-21 11:07 . 2008-01-21 11:07 <DIR> d--hs---- C:\Documents and Settings\Greg\UserData
2008-01-21 10:59 . 2008-01-21 10:59 2,422 --a------ C:\WINDOWS\system32\wpa.bak
2008-01-21 07:44 . 2008-02-01 15:52 <DIR> d-------- C:\Documents and Settings\Greg\Application Data\U3
2008-01-17 16:54 . 2008-01-28 13:23 <DIR> d-------- C:\Program Files\7-Zip
2008-01-17 16:51 . 2008-01-17 16:51 0 --a------ C:\WINDOWS\nsreg.dat
2008-01-17 16:21 . 2005-11-24 06:51 245,248 -ra------ C:\WINDOWS\system32\drivers\rt73.sys
2008-01-17 16:21 . 2003-10-13 15:30 94,208 --a------ C:\WINDOWS\system32\GTW32N50.dll
2008-01-17 16:21 . 2005-11-03 17:41 32,768 --a------ C:\WINDOWS\system32\GTGina.dll
2008-01-17 16:21 . 2003-09-25 23:28 31,930 --a------ C:\WINDOWS\system32\GTNDIS3.VXD
2008-01-17 16:21 . 2005-02-01 18:18 17,992 --a------ C:\WINDOWS\system32\drivers\bcm42rly.sys
2008-01-17 16:21 . 2005-02-01 18:18 17,992 --a------ C:\WINDOWS\system32\bcm42rly.sys
2008-01-17 16:21 . 2005-02-01 18:18 17,992 --a------ C:\WINDOWS\bcm42rly.sys
2008-01-17 16:21 . 2003-09-25 22:15 15,872 --a------ C:\WINDOWS\system32\GTNDIS5.sys
2008-01-17 16:17 . 2008-01-17 16:17 <DIR> d-------- C:\Program Files\directx
2008-01-17 16:17 . 2008-01-30 21:25 241 --a------ C:\WINDOWS\QSync.INI
2008-01-17 16:15 . 2008-01-22 16:18 <DIR> d-------- C:\WINDOWS\system32\FxsTmp
2008-01-17 16:15 . 2008-02-01 00:15 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-01-17 16:15 . 2008-01-17 16:16 <DIR> d-------- C:\Program Files\Common Files\Logitech
2008-01-17 16:14 . 2008-01-17 16:19 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2008-01-17 16:14 . 2008-01-17 16:14 <DIR> d-------- C:\Program Files\Windows Media Components
2008-01-17 16:14 . 2008-01-17 16:15 <DIR> d-------- C:\Program Files\Logitech
2008-01-17 16:12 . 2008-01-21 11:30 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-01-17 16:06 . 2008-01-17 16:06 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2008-01-17 16:06 . 2008-01-17 16:06 8,192 --a------ C:\WINDOWS\REGLOCS.OLD

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-02 07:12 43,520 ----a-w C:\WINDOWS\system32\drivers\fetnd5bv.sys
2007-12-14 16:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 17:54 127022]
"LogitechGalleryRepair"="C:\Program Files\Logitech\ImageStudio\ISStart.exe" [2002-12-10 18:32 155648]
"LogitechImageStudioTray"="C:\Program Files\Logitech\ImageStudio\LogiTray.exe" [2002-12-10 18:31 61440]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"VTTimer"="VTTimer.exe" [2005-03-08 04:33 53248 C:\WINDOWS\system32\VTTimer.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"LTMSG"="LTMSG.exe" [2003-07-14 10:52 40960 C:\WINDOWS\ltmsg.exe]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-06 19:05 200704]
"AVG7_CC"="J:\Software\AVG\avgcc.exe" [2008-01-22 19:42 579072]
"AVP"="J:\Software\KAV6\avp.exe" [2007-11-19 14:40 231952]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 07:00 15360]
"AVG7_Run"="J:\Software\AVG\avgw.exe" [2008-01-22 19:42 219136]

C:\Documents and Settings\Greg\Start Menu\Programs\Startup\
Random House Webster's College Dictionary WordGenius Activate.LNK - C:\Program Files\WordGenius\WGRC.exe [2008-01-21 20:16:55 75904]

S3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2008-01-02 02:12]
S3 LVBulk;LVBulk Service;C:\WINDOWS\system32\DRIVERS\LVBulk.sys [2002-09-20 15:15]
S3 PID_0960_V;Logitech ClickSmart 420(PID_0960_V);C:\WINDOWS\system32\DRIVERS\LVVIMULB.SYS [2002-09-20 15:19]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8bcc196a-c90e-11dc-b269-001c10e68a72}]
\Shell\AutoRun\command - M:\ek.com
\Shell\explore\Command - M:\ek.com
\Shell\open\Command - M:\ek.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{964c67d0-c81d-11dc-9e7a-ae6911b107fa}]
\Shell\AutoRun\command - N:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{964c67d1-c81d-11dc-9e7a-ae6911b107fa}]
\Shell\AutoRun\command - O:\8h3hh3m.exe
\Shell\explore\Command - O:\8h3hh3m.exe
\Shell\open\Command - O:\8h3hh3m.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-03 15:16:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-03 15:17:28
ComboFix-quarantined-files.txt 2008-02-03 20:17:12
.
2008-01-23 04:43:41 --- E O F ---





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:18:58 PM, on 03/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
J:\Software\Lavasoft\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
J:\Software\AVG\avgamsvr.exe
J:\Software\AVG\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
J:\Software\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [AVG7_CC] J:\Software\AVG\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVP] "J:\Software\KAV6\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] J:\Software\AVG\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Random House Webster's College Dictionary WordGenius Activate.LNK = C:\Program Files\WordGenius\WGRC.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1200974219031
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - J:\Software\Lavasoft\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - J:\Software\AVG\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - J:\Software\AVG\avgupsvc.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - J:\Software\KAV6\avp.exe

--
End of file - 4747 bytes
LoPhatPhuud
There was still a piece of Kavo running loose.

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

QUOTE
File::
C:\WINDOWS\system32\kavo.exe
O:\8h3hh3m.exe

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{964c67d1-c81d-11dc-9e7a-ae6911b107fa}]


Save this as CFScript.txt, in the same location as ComboFix.exe




Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Gr3g
Thanks again for the help after running combofix once i saw quite an improvement.
ComboFix 08-02.03.1 - Greg 2008-02-05 21:47:24.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.131 [GMT -5:00]
Running from: C:\Documents and Settings\Greg\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Greg\Desktop\CFScript.txt.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\system32\kavo.exe
O:\8h3hh3m.exe
.

((((((((((((((((((((((((( Files Created from 2008-01-06 to 2008-02-06 )))))))))))))))))))))))))))))))
.

2008-02-05 21:45 . 2004-08-04 07:00 388,608 --a------ C:\kmd.exe
2008-02-05 13:11 . 2008-02-05 13:11 45 --a------ C:\TEST.XML
2008-02-04 17:01 . 2008-02-04 17:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-02-04 17:01 . 2007-11-14 16:05 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-02-04 17:01 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-02-04 17:01 . 2008-02-05 18:12 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-02-04 16:59 . 2008-02-05 21:43 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-02-04 13:14 . 2008-02-04 13:14 <DIR> d-------- C:\Program Files\TGTSoft
2008-02-03 18:51 . 2008-02-03 18:52 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\AVG7
2008-02-01 00:14 . 2008-02-01 00:14 <DIR> d-------- C:\Program Files\Canon
2008-02-01 00:11 . 2008-02-01 00:11 <DIR> d--h----- C:\CanonMF
2008-02-01 00:10 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-02-01 00:10 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-01-31 00:58 . 2008-01-31 00:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-31 00:54 . 2008-01-31 00:54 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-31 00:31 . 2008-01-31 00:31 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-01-30 00:09 . 2008-01-30 00:10 <DIR> d-------- C:\Dev-C++
2008-01-30 00:08 . 1996-07-18 13:06 297,472 --a------ C:\WINDOWS\uninst.exe
2008-01-29 23:13 . 2008-01-29 23:13 <DIR> d-------- C:\Documents and Settings\Greg\WINDOWS
2008-01-29 22:11 . 2008-01-29 22:11 <DIR> d-------- C:\Program Files\uTorrent
2008-01-29 22:11 . 2008-02-05 21:42 <DIR> d-------- C:\Documents and Settings\Greg\Application Data\uTorrent
2008-01-29 21:14 . 2008-02-05 00:31 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2008-01-25 13:35 . 2008-02-05 21:49 4,288,288 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-25 13:35 . 2008-02-04 13:42 78,624 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-25 13:35 . 2008-02-05 14:16 63,764 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-25 13:35 . 2008-02-04 13:42 10,532 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-25 13:31 . 2008-01-25 13:31 <DIR> d-------- C:\KAV
2008-01-24 15:36 . 2008-01-24 15:37 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-01-22 22:23 . 2008-01-22 22:23 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-01-22 22:21 . 2004-09-09 21:30 57,344 --a------ C:\WINDOWS\system32\CNARLMNT.DLL
2008-01-22 22:21 . 2004-09-09 21:31 53,248 --a------ C:\WINDOWS\system32\cncilps1.dll
2008-01-22 22:21 . 2003-08-20 15:16 22,048 --a------ C:\WINDOWS\system32\cocpyinf.dll
2008-01-22 19:43 . 2008-01-22 19:43 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-22 19:43 . 2008-02-05 13:51 <DIR> d-------- C:\Documents and Settings\Greg\Application Data\AVG7
2008-01-22 19:43 . 2008-01-22 19:43 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-01-22 19:43 . 2008-01-22 19:43 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-01-22 19:42 . 2008-01-22 19:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-22 19:42 . 2008-01-22 19:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-01-22 19:30 . 2004-08-04 00:56 90,624 --a------ C:\WINDOWS\system32\kswdmcap.ax
2008-01-22 19:30 . 2004-08-04 00:56 90,624 --a--c--- C:\WINDOWS\system32\dllcache\kswdmcap.ax
2008-01-22 19:30 . 2004-08-04 00:56 61,952 --a------ C:\WINDOWS\system32\kstvtune.ax
2008-01-22 19:30 . 2004-08-04 00:56 61,952 --a--c--- C:\WINDOWS\system32\dllcache\kstvtune.ax
2008-01-22 19:30 . 2004-08-04 00:56 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2008-01-22 19:30 . 2004-08-04 00:56 53,760 --a--c--- C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2008-01-22 19:30 . 2004-08-04 00:56 43,008 --a------ C:\WINDOWS\system32\ksxbar.ax
2008-01-22 19:30 . 2004-08-04 00:56 43,008 --a--c--- C:\WINDOWS\system32\dllcache\ksxbar.ax
2008-01-22 19:30 . 2004-08-04 00:56 28,672 --a------ C:\WINDOWS\system32\vidcap.ax
2008-01-22 19:30 . 2004-08-04 00:56 28,672 --a--c--- C:\WINDOWS\system32\dllcache\vidcap.ax
2008-01-22 13:16 . 2008-01-22 13:16 <DIR> d-------- C:\Program Files\Microsoft Works
2008-01-22 13:15 . 2008-01-22 13:15 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-01-22 13:12 . 2008-01-22 13:16 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-01-22 13:11 . 2008-01-22 13:11 <DIR> dr-h----- C:\MSOCache
2008-01-22 13:11 . 2008-02-04 12:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-22 12:28 . 2008-01-22 12:28 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-01-22 12:25 . 2008-01-22 12:25 <DIR> d-------- C:\Program Files\Instant CD & DVD Burner
2008-01-22 11:51 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-01-22 11:51 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-01-21 23:41 . 2008-01-21 23:41 268 --ah----- C:\sqmdata00.sqm
2008-01-21 23:41 . 2008-01-21 23:41 244 --ah----- C:\sqmnoopt00.sqm
2008-01-21 23:20 . 2008-01-21 23:20 <DIR> d-------- C:\Program Files\MSBuild
2008-01-21 23:17 . 2008-02-04 12:27 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-01-21 23:16 . 2008-01-21 23:16 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-01-21 23:15 . 2008-01-31 22:13 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-01-21 23:15 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-01-21 23:14 . 2008-01-21 23:14 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-01-21 23:14 . 2008-01-21 23:14 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-01-21 23:07 . 2008-01-21 23:08 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-01-21 23:04 . 2006-11-13 01:02 288,768 --------- C:\WINDOWS\system32\rhttpaa.dll
2008-01-21 23:04 . 2006-11-13 01:02 116,736 --------- C:\WINDOWS\system32\aaclient.dll
2008-01-21 23:04 . 2006-11-13 01:02 36,352 --------- C:\WINDOWS\system32\tsgqec.dll
2008-01-21 20:16 . 2008-01-31 22:14 <DIR> d-------- C:\Program Files\WordGenius
2008-01-21 20:16 . 2008-02-05 21:36 274 --a------ C:\WINDOWS\WGRC.INI
2008-01-21 20:14 . 2008-01-21 20:14 <DIR> d-------- C:\Documents and Settings\Greg\Contacts
2008-01-21 20:13 . 2008-01-21 20:13 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-01-21 20:11 . 2008-01-21 20:13 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-21 20:10 . 2008-01-21 20:13 <DIR> d-------- C:\Program Files\Windows Live
2008-01-21 20:10 . 2008-01-21 20:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-21 20:09 . 2008-01-21 20:09 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-01-21 11:31 . 2008-01-21 11:31 <DIR> d-------- C:\Program Files\VIA
2008-01-21 11:31 . 2005-03-09 11:17 11,692 --a------ C:\WINDOWS\system32\hg201hp.inf
2008-01-21 11:29 . 2004-09-20 15:20 16,121,856 --a------ C:\WINDOWS\system32\ALSNDMGR.CPL
2008-01-21 11:16 . 2008-01-22 11:57 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-01-21 11:16 . 2006-10-16 16:10 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-01-21 11:07 . 2008-01-21 11:07 <DIR> d--hs---- C:\Documents and Settings\Greg\UserData
2008-01-21 10:59 . 2008-01-21 10:59 2,422 --a------ C:\WINDOWS\system32\wpa.bak
2008-01-21 07:44 . 2008-02-01 15:52 <DIR> d-------- C:\Documents and Settings\Greg\Application Data\U3
2008-01-17 16:54 . 2008-01-28 13:23 <DIR> d-------- C:\Program Files\7-Zip
2008-01-17 16:51 . 2008-01-17 16:51 0 --a------ C:\WINDOWS\nsreg.dat
2008-01-17 16:21 . 2005-11-24 06:51 245,248 -ra------ C:\WINDOWS\system32\drivers\rt73.sys
2008-01-17 16:21 . 2003-10-13 15:30 94,208 --a------ C:\WINDOWS\system32\GTW32N50.dll
2008-01-17 16:21 . 2005-11-03 17:41 32,768 --a------ C:\WINDOWS\system32\GTGina.dll
2008-01-17 16:21 . 2003-09-25 23:28 31,930 --a------ C:\WINDOWS\system32\GTNDIS3.VXD
2008-01-17 16:21 . 2005-02-01 18:18 17,992 --a------ C:\WINDOWS\system32\drivers\bcm42rly.sys
2008-01-17 16:21 . 2005-02-01 18:18 17,992 --a------ C:\WINDOWS\system32\bcm42rly.sys
2008-01-17 16:21 . 2005-02-01 18:18 17,992 --a------ C:\WINDOWS\bcm42rly.sys
2008-01-17 16:21 . 2003-09-25 22:15 15,872 --a------ C:\WINDOWS\system32\GTNDIS5.sys
2008-01-17 16:17 . 2008-01-17 16:17 <DIR> d-------- C:\Program Files\directx
2008-01-17 16:17 . 2008-01-30 21:25 241 --a------ C:\WINDOWS\QSync.INI
2008-01-17 16:15 . 2008-01-22 16:18 <DIR> d-------- C:\WINDOWS\system32\FxsTmp
2008-01-17 16:15 . 2008-02-01 00:15 <DIR> d--h----- C:\Program Files\InstallShield Installation Information

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-02 07:12 43,520 ----a-w C:\WINDOWS\system32\drivers\fetnd5bv.sys
2007-12-14 16:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-11-14 21:05 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 13:31 1372160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 17:54 127022]
"LogitechGalleryRepair"="C:\Program Files\Logitech\ImageStudio\ISStart.exe" [2002-12-10 18:32 155648]
"LogitechImageStudioTray"="C:\Program Files\Logitech\ImageStudio\LogiTray.exe" [2002-12-10 18:31 61440]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"VTTimer"="VTTimer.exe" [2005-03-08 04:33 53248 C:\WINDOWS\system32\VTTimer.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"LTMSG"="LTMSG.exe" [2003-07-14 10:52 40960 C:\WINDOWS\ltmsg.exe]
"AVG7_CC"="J:\Software\AVG\avgcc.exe" [2008-01-22 19:42 579072]
"ZoneAlarm Client"="J:\Software\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 07:00 15360]
"AVG7_Run"="J:\Software\AVG\avgw.exe" [2008-01-22 19:42 219136]

C:\Documents and Settings\Greg\Start Menu\Programs\Startup\
Random House Webster's College Dictionary WordGenius Activate.LNK - C:\Program Files\WordGenius\WGRC.exe [2008-01-21 20:16:55 75904]

R3 LVBulk;LVBulk Service;C:\WINDOWS\system32\DRIVERS\LVBulk.sys [2002-09-20 15:15]
R3 PID_0960_V;Logitech ClickSmart 420(PID_0960_V);C:\WINDOWS\system32\DRIVERS\LVVIMULB.SYS [2002-09-20 15:19]
S3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2008-01-02 02:12]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8bcc196a-c90e-11dc-b269-001c10e68a72}]
\Shell\AutoRun\command - M:\ek.com
\Shell\explore\Command - M:\ek.com
\Shell\open\Command - M:\ek.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{964c67d0-c81d-11dc-9e7a-ae6911b107fa}]
\Shell\AutoRun\command - N:\LaunchU3.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-05 21:50:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-05 21:50:39
ComboFix-quarantined-files.txt 2008-02-06 02:50:35
ComboFix2.txt 2008-02-03 20:17:29
.
2008-01-23 04:43:41 --- E O F ---
LoPhatPhuud
That last ComboFix log looked good. Run HiJackThis again and post a new log in this thread for a final check, please.
Gr3g
Here's that hjackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:10:08 PM, on 07/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
J:\Software\Lavasoft\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
J:\Software\AVG\avgamsvr.exe
J:\Software\AVG\avgupsvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\LTMSG.exe
J:\Software\AVG\avgcc.exe
J:\Software\ZoneAlarm\zlclient.exe
J:\Software\AVG\avgw.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
J:\Software\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [AVG7_CC] J:\Software\AVG\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ZoneAlarm Client] "J:\Software\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] J:\Software\AVG\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Random House Webster's College Dictionary WordGenius Activate.LNK = C:\Program Files\WordGenius\WGRC.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1200974219031
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - J:\Software\Lavasoft\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - J:\Software\AVG\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - J:\Software\AVG\avgupsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 4613 bytes
LoPhatPhuud
Your HJT was clean too. We are done, unless there are issues outstanding that are not reflected in your log(s).
Gr3g
Thanks for the help LoPhatPhuud
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.