Here is the ComboFix log...
ComboFix 09-10-23.01 - Administrator 10/24/2009 22:26.5.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.959.608 [GMT 8:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\BcHCMJEEXFxaCm3q.Ttf
c:\windows\Downloaded Program Files\EBC5d44wguttJ5GpMYy.Ttf
c:\windows\Downloaded Program Files\hyxqXj4ENYN8PTavg.Ttf
c:\windows\Downloaded Program Files\jEDR2jykhSujaMqF.Ttf
c:\windows\Downloaded Program Files\kAva4a5fpFR2ySmpM.Ttf
c:\windows\Downloaded Program Files\rJaeKv7CcbwSzhQbDu.cur
c:\windows\Downloaded Program Files\SjRjQgREDp3P8B4rEEg.cur
c:\windows\Downloaded Program Files\SvS2DJAqqTvtTYEU.Ttf
c:\windows\Downloaded Program Files\sZaeAC74EzXJeVeJu6p.cur
c:\windows\Downloaded Program Files\u8w23uRSuevxt2VP.Ttf
c:\windows\Downloaded Program Files\uMub3WCE6aZ3nFgrYRX.Ttf
c:\windows\Downloaded Program Files\Unt9DSsEC4mzsuy6GV.Ttf
c:\windows\Downloaded Program Files\WD2B9pAnWGBjB2sz.Ttf
c:\windows\Downloaded Program Files\WeTqkj55B2u5bVUqbj.Ttf
c:\windows\Downloaded Program Files\WQKrDGnXQQb3Mgjk.Ttf
c:\windows\Downloaded Program Files\WUSTnjhyfqfpv8pqbc.cur
c:\windows\Fonts\2knxWtVjbWXmUdGG.Ttf
c:\windows\Fonts\A97CRaCB.fon
c:\windows\Fonts\cFDPmh3MDPjcHMPd.Ttf
c:\windows\Fonts\CRp3uYCmcxMp3qQn9.Ttf
c:\windows\Fonts\eCgMhGRkPUcdutd0.Ttf
c:\windows\Fonts\eSEWZRdrSK3NeEJVy4.Ttf
c:\windows\Fonts\fontgsdgsddg.td
c:\windows\Fonts\G8qZ5hBX7H.Ttf
c:\windows\Fonts\HXxfduw9KeQTCeP6Z.Ttf
c:\windows\Fonts\qWskzsQA6.Ttf
c:\windows\Fonts\RCZbVbjCY6wYszD3.Ttf
c:\windows\Fonts\tBeuadwPppCBnDUPgJH7P6.Ttf
c:\windows\system32\08223B03.dll
c:\windows\system32\122B901E.dll
c:\windows\system32\2eXJw3dsatgwrf5uapadmhn.dll
c:\windows\system32\AMNCZw74h8gwd6CpYGkrZDy8.inf
c:\windows\system32\BtmBAnd89jc9PsPq5EKNj.inf
c:\windows\system32\bWxJAeWKDxgRfhkaWEfA33C36nr.in f
c:\windows\system32\CDuAUVkGy9.dll
c:\windows\system32\dllcache\lsasvc.dll
c:\windows\system32\FsMBy3kmwnag5grbwggu.inf
c:\windows\system32\Je9hR9NedWPyAckEN42c.inf
c:\windows\system32\jY8sGUnWqbZb3x2BPhY.dll
c:\windows\system32\ndXQ9awmc.dll
c:\windows\system32\nXe2grrKNzF9dxYKmqg.inf
c:\windows\system32\PERrGx5DkqSbQdwauCRQH.dll
c:\windows\system32\qzp3jTZCSfSh.dll
c:\windows\system32\rb37sCqvGmszGJ3aQYB5qRczx.inf
c:\windows\system32\SCEVfjrcmab7.dll
c:\windows\system32\t9hdtMrwMeQcvYV3CMvhtNZpC.inf
c:\windows\system32\WQVBYhAJ6ADw5qzCY8gv84KTH.inf
c:\windows\system32\z6FVkef47hupzgaxee.inf
c:\windows\Tasks\c2NH4numz9kny5zqnc.inf
c:\windows\Tasks\EfEPEaD4ZpVMUXrDbS.inf
c:\windows\Tasks\EkKXXTKa2TVmc6XM.ico
c:\windows\Tasks\JJX5r8wnsqUnNxGwpwn.inf
c:\windows\Tasks\kTS4JJGUYtVagxPs.ico
c:\windows\Tasks\kZdWDEpQcNC2NwDe.ico
c:\windows\Tasks\SbrmpxjdCrgRAFhz4gHh.inf
c:\windows\Tasks\shrjrubbVVReN7yY.ico
c:\windows\Tasks\TDz5y2TEAKw2z7xkPhf9Sqj.inf
c:\windows\Tasks\ThGkkhVnR6Dhf3eN.ico
c:\windows\Tasks\TQupe3tz9FGwu56yjWvyY4t.inf
c:\windows\Tasks\vC6ykXbjUGCVeCJa.ico
c:\windows\Tasks\x7j7yet9WK9FdYSD.ico
c:\windows\Tasks\xbkp74yhxPwfnz6Qc.ico
c:\windows\Tasks\yGFDvuegeqm9fhy5rnn.inf
Infected copy of c:\windows\system32\qmgr.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\qmgr.dll
.
((((((((((((((((((((((((( Files Created from 2009-09-24 to 2009-10-24 )))))))))))))))))))))))))))))))
.
2009-10-24 14:05 . 2009-10-24 14:05 -------- d-----w- c:\program files\Trend Micro
2009-10-23 11:29 . 2004-08-04 12:00 792064 ------w- c:\windows\system32\comres.dll
2009-10-22 12:58 . 2009-10-22 12:58 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-10-22 12:58 . 2009-10-22 12:58 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-10-22 12:58 . 2009-10-22 12:58 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-10-22 12:58 . 2009-10-22 12:58 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-22 12:27 . 2009-10-22 12:27 -------- d-----w- c:\program files\Common Files\Thunder Network
2009-10-22 12:27 . 2009-10-22 12:27 -------- d-----w- c:\program files\Common Files\Java
2009-10-21 11:47 . 2009-10-21 11:47 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Identities
2009-10-17 16:04 . 2009-10-17 16:06 -------- d-----w- C:\BOXING
2009-10-14 02:33 . 2009-10-14 02:33 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Temp
2009-10-13 11:00 . 2009-10-13 11:01 -------- d-----w- c:\documents and settings\Administrator\Application Data\dvdcss
2009-10-13 09:05 . 2005-05-18 02:55 32768 ----a-w- c:\windows\VMZoom.exe
2009-10-13 09:05 . 2005-05-18 02:54 24576 ----a-w- c:\windows\VMPipe.dll
2009-10-13 09:05 . 2009-10-13 09:05 -------- d-----w- c:\windows\EffectResources
2009-10-13 09:05 . 2009-10-13 09:05 -------- d-----w- c:\windows\CatRoot
2009-10-13 09:05 . 2009-10-13 09:05 -------- d-----w- c:\program files\Vimicro
2009-10-13 09:05 . 2005-10-27 06:34 390849 ----a-w- c:\windows\system32\drivers\usbVM303.sys
2009-10-13 09:05 . 2005-10-25 04:56 61440 ----a-w- c:\windows\VM303_STI.EXE
2009-10-13 09:05 . 2005-05-03 07:51 176128 ----a-w- c:\windows\amcap.exe
2009-10-13 09:05 . 2005-05-02 08:45 53248 ----a-w- c:\windows\Sti303.exe
2009-10-13 09:05 . 2005-04-30 10:46 81920 ----a-w- c:\windows\system32\VM303STI.dll
2009-10-13 09:05 . 2005-04-30 10:46 102400 ----a-w- c:\windows\VM303Cap.exe
2009-10-13 08:50 . 2004-08-03 15:08 26496 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-10-24 14:29 . 2009-10-12 14:57 -------- d-----w- c:\documents and settings\Administrator\Application Data\uTorrent
2009-10-24 08:35 . 2009-10-12 15:40 -------- d-----w- c:\documents and settings\Administrator\Application Data\vlc
2009-10-22 12:25 . 2004-08-04 12:00 121856 ----a-w- c:\windows\system32\stobject.dll
2009-10-22 12:21 . 2009-10-12 15:26 -------- d-----w- c:\documents and settings\Administrator\Application Data\Winamp
2009-10-19 10:17 . 2009-10-12 15:39 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-13 09:05 . 2009-10-12 14:43 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-13 09:05 . 2009-10-12 14:40 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-12 16:26 . 2009-10-12 16:26 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-10-12 16:25 . 2009-10-12 16:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-12 15:56 . 2009-10-12 15:56 -------- d-----w- c:\program files\Microsoft.NET
2009-10-12 15:56 . 2009-10-12 15:56 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-10-12 15:47 . 2009-10-12 15:47 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-10-12 15:45 . 2009-10-12 15:45 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-10-12 15:45 . 2009-10-12 15:45 -------- d-----w- c:\documents and settings\Administrator\Application Data\DAEMON Tools
2009-10-12 15:44 . 2009-10-12 15:44 -------- d-----w- c:\program files\Realtek Sound Manager
2009-10-12 15:44 . 2009-10-12 15:44 -------- d-----w- c:\program files\AvRack
2009-10-12 15:44 . 2009-10-12 15:44 -------- d-----w- c:\program files\Realtek AC97
2009-10-12 15:35 . 2009-10-12 15:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-10-12 15:35 . 2009-10-12 15:35 -------- d-----w- c:\program files\Yahoo!
2009-10-12 15:26 . 2009-10-12 15:26 0 ----a-w- c:\windows\nsreg.dat
2009-10-12 15:17 . 2009-10-12 15:17 -------- d-----w- c:\program files\Google
2009-10-12 14:46 . 2009-10-12 14:46 -------- d-----w- c:\program files\S3
2009-10-12 14:40 . 2009-10-12 14:40 -------- d-----w- c:\program files\VIA
2009-10-12 14:40 . 2009-10-12 14:40 12328 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-12 14:32 . 2009-10-12 14:32 -------- d-----w- c:\program files\microsoft frontpage
2009-10-12 14:28 . 2009-10-12 14:28 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-09-10 06:54 . 2009-10-12 16:25 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 06:53 . 2009-10-12 16:25 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2004-08-04 12:00 . 2004-08-04 12:00 156691 --sha-r- c:\windows\system32\dohgym.dll
.
------- Sigcheck -------
[-] 2004-08-04 . D4F0A03B16D472480F6FFEF4E16EA07D . 245248 . . [5.1.2600.2180] . . c:\windows\system32\mswsock.dll
[7] 2004-08-04 . 4E74AF063C3271FBEA20DD940CFD1184 . 245248 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\mswsock.dll
[-] 2004-08-04 12:00 . 5C251679EBBEA471E7175EAD040529BD . 43520 . . [------] . . c:\windows\system32\xmlprov.dll
[7] 2004-08-04 . EEF46DAB68229A14DA3D8E73C99E2959 . 129536 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\xmlprov.dll
[-] 2009-03-21 . 32272BF10467C8ACF1F83138C61D541E . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
[7] 2005-01-28 05:44 . 140EF97B64F560FD78643CAE2CDAD838 . 25088 . . [10.0.3790.3802] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll
[7] 2004-08-04 12:00 . C086483E3DBA8C1C0A687EC8D5B3D4C1 . 52224 . . [9.0.1.56] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSNSv.dll
[7] 2002-11-26 11:03 . 36678803A8030EE9A771935CFC1848BD . 52224 . . [9.0.1.56] . . c:\windows\RegisteredPackages\{A0000BA0-97AD-43FB-8A05-3542C3AB99CD}\mspmsnsv.dll
[-] 2002-11-26 11:03 . CAAC5C1A725D6FCD90D86612582133EB . 42496 . . [------] . . c:\windows\system32\mspmsnsv.dll
[7] 2002-11-26 11:03 . 36678803A8030EE9A771935CFC1848BD . 52224 . . [9.0.1.56] . . c:\windows\system32\dllcache\mspmsnsv.dll
[7] 2004-08-04 12:00 . B62F29C00AC55A761B2E45877D85EA0F . 435200 . . [5.1.2400.2180] . . c:\windows\ERDNT\cache\ntmssvc.dll
[-] 2004-08-04 12:00 . CAAC5C1A725D6FCD90D86612582133EB . 42496 . . [------] . . c:\windows\system32\ntmssvc.dll
[7] 2004-08-04 12:00 . B62F29C00AC55A761B2E45877D85EA0F . 435200 . . [5.1.2400.2180] . . c:\windows\system32\dllcache\ntmssvc.dll
[7] 2004-08-04 . 0546477BDE979E33294FE97F6B3DE84A . 185344 . . [5.1.2600.2180] . . c:\windows\ERDNT\cache\upnphost.dll
[-] 2004-08-04 12:00 . CAAC5C1A725D6FCD90D86612582133EB . 42496 . . [------] . . c:\windows\system32\upnphost.dll
[7] 2004-08-04 . 0546477BDE979E33294FE97F6B3DE84A . 185344 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\upnphost.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-10-22_12.35.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-22 12:58 . 2009-10-22 12:58 65024 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2009-10-22 12:58 . 2009-10-22 12:58 18944 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2009-10-22 12:58 . 2009-10-22 12:58 5120 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe
+ 2009-10-22 12:58 . 2009-10-22 12:58 1583616 c:\windows\Installer\158171.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"uTorrent"="d:\program files\uTorrent\uTorrent.exe" [2009-10-01 289072]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-04 486856]
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{30E05169-5E63-4038-9709-5FAD6E488ED2}"= "c:\windows\system32\rb37sCqvGmszGJ3aQYB5qRczx.inf " [BU]
"{F317E464-D4A4-4C79-82E8-CABADF738C7C}"= "c:\windows\system32\t9hdtMrwMeQcvYV3CMvhtNZpC.inf " [BU]
"{C4BD9D5C-04CA-45E6-8539-98B07D99B6BC}"= "c:\windows\system32\AMNCZw74h8gwd6CpYGkrZDy8. inf" [BU]
"{D55E3C90-C192-411F-85FC-6A8A69D0C634}"= "c:\windows\system32\WQVBYhAJ6ADw5qzCY8gv84KTH.inf " [BU]
"{81EB905C-EDF8-4033-80BF-E0F4F46733DF}"= "c:\windows\Tasks\TDz5y2TEAKw2z7xkPhf9Sqj.inf" [BU]
"{05EDDA35-1E5B-4A77-8F68-99AB967CF632}"= "c:\windows\system32\bWxJAeWKDxgRfhkaWEfA33C36nr.i nf" [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 07:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
"UPS"=3 (0x3)
"Spooler"=2 (0x2)
"ImapiService"=3 (0x3)
"ALG"=3 (0x3)
"ose"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"3961:TCP"= 3961:TCP:bbcckgsb
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [10/12/2009 10:42 PM 11264]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/12/2009 9:24 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/12/2009 9:24 PM 74480]
S2 imivsh;Universal Monitor;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 8:00 PM 14336]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [10/12/2009 9:24 PM 7408]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
imivsh
.
Contents of the 'Scheduled Tasks' folder
2009-10-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-2147080445-682003330-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-12 15:18]
2009-10-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220945662-2147080445-682003330-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-12 15:18]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\gdaf2k58.default\
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: d:\program files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
.
- - - - ORPHANS REMOVED - - - -
ShellExecuteHooks-{F181F067-7046-4DCB-993F-200990736305} - (no file)
ShellExecuteHooks-{F7D81EAE-34CD-4EC5-9663-37FC799F1B50} - (no file)
ShellExecuteHooks-{FF9896FF-88E7-4D7F-8839-5A7C5D062F3B} - (no file)
ShellExecuteHooks-{07B2788F-BD22-404E-B617-4ABCA2C0BF94} - (no file)
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2009-10-24 22:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\i mivsh]
"ServiceDll"="c:\windows\system32\dohgym.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(696)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'explorer.exe'(332)
c:\program files\Messenger\dcap32.dll
c:\program files\Common Files\Java\bin\eula.dll
c:\program files\Internet Explorer\iedw.dll
c:\program files\Common Files\Thunder Network\KanKan\DapCtrl.dll
c:\program files\WinRar\ZipExt.dll
.
------------------------ Other Running Processes ------------------------
.
c:\combofix\CF29209.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Internet Explorer\iexplore.exe
c:\combofix\PEV.cfxxe
.
************************************************** ************************
.
Completion time: 2009-10-24 22:32 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-24 14:32
ComboFix2.txt 2009-10-24 03:39
ComboFix3.txt 2009-10-23 11:32
ComboFix4.txt 2009-10-22 12:43
ComboFix5.txt 2009-10-24 14:26
Pre-Run: 13,115,142,144 bytes free
Post-Run: 13,093,642,240 bytes free
- - End Of File - - 2ABA5C6C59AA7BAA893B429E82D1C31F
-----
New Hijack this log
-------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:31:44 AM, on 10/25/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Bing
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKCU\..\Run: [uTorrent] "D:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACA44DAA-F941-4928-BC6E-22A1D3B1E1CB}: NameServer = 202.78.97.41 210.4.2.61
O20 - AppInit_DLLs: C:\WINDOWS\Downloaded Program Files\rJaeKv7CcbwSzhQbDu.cur,
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
--
End of file - 2810 bytes
----
Uninstall list
µTorrent
A4 TECH USB PC Camera H
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.2
Google Talk (remove only)
HijackThis 2.0.2
iriver plus 3 (remove only)
Malwarebytes' Anti-Malware
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.5.3)
Realtek AC'97 Audio
SUPERAntiSpyware Free Edition
VIA Platform Device Manager
VIA/S3G Display Driver
VLC media player 1.0.1
Winamp
Windows Media Format Runtime
WinRAR archiver
Yahoo! Messenger
----
startup list
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\notepad.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
uTorrent = "D:\Program Files\uTorrent\uTorrent.exe"
DAEMON Tools Lite = "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[OptionalComponents]
=
--------------------------------------------------
Load/Run keys from C:\WINDOWS\WIN.INI:
load=*INI section not found*
run=*INI section not found*
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=C:\WINDOWS\Downloaded Program Files\rJaeKv7CcbwSzhQbDu.cur,
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper Objects:
AcroIEHelperStub - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
--------------------------------------------------
Enumerating Task Scheduler jobs:
GoogleUpdateTaskUserS-1-5-21-1220945662-2147080445-682003330-500Core.job
GoogleUpdateTaskUserS-1-5-21-1220945662-2147080445-682003330-500UA.job
--------------------------------------------------
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\Program Files\Messenger\dcap32.dll|||e
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
--------------------------------------------------
End of report, 5,676 bytes
Report generated in 0.031 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Thanks...