I have created the log file per your instructions, but I'm unclear on your instructions on how to upload the log file. I will paste the log file below. Thank you for your help so far with this.
ComboFix 07-11-08.3 - Owner 2007-11-13 20:00:29.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.
Running from: C:\Documents and Settings\Owner\Desktop\Com
* Created a new restore point
.
((((((((((((((((((((((((((
.
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\Application
C:\Documents and Settings\Owner\My Documents\CROSOF~1.NET
C:\Documents and Settings\Owner\My Documents\DOBE~1
C:\Documents and Settings\Owner\My Documents\ICROSO~1.NET
C:\Documents and Settings\Owner\My Documents\PPPATC~1
C:\Documents and Settings\Owner\My Documents\SSEMBL~1
C:\Documents and Settings\Owner\My Documents\STEM32~1
C:\Documents and Settings\Owner\My Documents\YMANTE~1
C:\Program Files\asks~1
C:\Program Files\asks~1\m?dtc.exe
C:\Program Files\cas
C:\Program Files\Common Files\fnts~1
C:\Program Files\Common Files\icroso~1.net
C:\Program Files\fnts~1
C:\Program Files\stem~1
C:\WINDOWS\cookies.ini
C:\WINDOWS\fnts~1
C:\WINDOWS\mcroso~1
C:\WINDOWS\ssembl~1
C:\WINDOWS\system32\ecurit
C:\WINDOWS\system32\kdabxb
C:\WINDOWS\ymbols~1
.
((((((((((((((((((((((((((
.
-------\LEGACY_DOMAINSERVI
-------\LEGACY_PWMDVPAX
-------\pwmdvpax
((((((((((((((((((((((((( Files Created from 2007-10-14 to 2007-11-14 ))))))))))))))))))))))))))
.
2007-11-13 19:59 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-12 20:36 <DIR> d-------- C:\Documents and Settings\Owner\Application
2007-11-12 20:36 <DIR> d-------- C:\Documents and Settings\LocalService\Appl
2007-11-12 20:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-12 20:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2007-11-12 14:28 <DIR> d-------- C:\Documents and Settings\Owner\Application
2007-11-12 14:08 6,058,496 -----c--- C:\WINDOWS\system32\dllcac
2007-11-12 14:08 2,455,488 -----c--- C:\WINDOWS\system32\dllcac
2007-11-12 14:08 459,264 -----c--- C:\WINDOWS\system32\dllcac
2007-11-12 14:08 383,488 -----c--- C:\WINDOWS\system32\dllcac
2007-11-12 14:08 267,776 -----c--- C:\WINDOWS\system32\dllcac
2007-11-12 14:08 63,488 -----c--- C:\WINDOWS\system32\dllcac
2007-11-12 14:08 52,224 -----c--- C:\WINDOWS\system32\dllcac
2007-11-12 14:08 13,824 -----c--- C:\WINDOWS\system32\dllcac
2007-11-12 14:01 33,792 --a--c--- C:\WINDOWS\system32\dllcac
2007-11-12 13:49 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-11-12 13:40 128,896 -----c--- C:\WINDOWS\system32\dllcac
2007-11-12 13:40 23,040 -----c--- C:\WINDOWS\system32\dllcac
2007-11-12 13:40 16,896 -----c--- C:\WINDOWS\system32\dllcac
2007-11-12 13:37 582,656 --a--c--- C:\WINDOWS\system32\dllcac
2007-11-12 13:22 55,333 --a------ C:\tmp1D.tmp.exe
2007-11-12 09:05 221,184 --a------ C:\WINDOWS\system32\wmpns.
2007-11-12 09:03 <DIR> d-------- C:\WINDOWS\provisioning
2007-11-12 09:03 <DIR> d-------- C:\WINDOWS\peernet
2007-11-12 08:58 <DIR> d-------- C:\WINDOWS\ServicePackFile
2007-11-12 08:43 <DIR> d-------- C:\WINDOWS\EHome
2007-11-12 08:00 <DIR> d-------- C:\WINDOWS\pss
2007-10-14 20:39 11,776 --------- C:\WINDOWS\system32\spnpin
2007-10-14 20:39 4,569 --------- C:\WINDOWS\system32\secupd
.
((((((((((((((((((((((((((
.
2007-11-13 01:15 --------- d-----w C:\Program Files\ItsDeductibleEX
2007-11-12 19:30 --------- d-----w C:\Program Files\Lavasoft
2007-11-12 19:30 --------- d-----w C:\Documents and Settings\Owner\Application
2007-10-23 15:48 5,120 ----a-w C:\WINDOWS\system32\driver
2007-10-23 15:48 18,688 ----a-w C:\WINDOWS\system32\driver
2007-10-14 02:22 --------- d-----w C:\Program Files\Opera
2007-10-03 10:02 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2007-10-02 05:50 --------- d-----w C:\Program Files\Windows Live Safety Center
2007-09-30 20:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-09-29 05:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Spyware
2007-09-13 18:48 55,333 ----a-w C:\tmp12.tmp.exe
.
((((((((((((((((((((((((((
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Brow
2003-07-16 15:26 101888 --a------ C:\WINDOWS\System32\dgsetu
[HKEY_LOCAL_MACHINE\~\Brow
C:\WINDOWS\system32\kbd__J
[HKEY_LOCAL_MACHINE\~\Brow
C:\WINDOWS\System32\cloqvl
[HKEY_LOCAL_MACHINE\SOFTWA
"IgfxTray"="C:\WINDOWS\Sys
"HotKeysCmds"="C:\WINDOWS\
"QBCD Autorun"="D:\autorun.exe" []
"NeroFilterCheck"="C:\WIND
"EPSON Stylus CX5400"="C:\WINDOWS\System
"magicolor 2300WStatusDisplay"="C:\WI
"tgcmd"="C:\Program Files\Support.com\BellSout
"dvd43"="C:\Program Files\dvd43\dvd43_tray.exe
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\reals
"SunJavaUpdateSched"="C:\P
"IntelliPoint"="C:\Program
"WUSB54Gv4"="C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\InvokeSvc3.exe" [2004-04-19 09:19]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.ex
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe
"AVG7_CC"="C:\PROGRA~1\Gri
[HKEY_CURRENT_USER\SOFTWAR
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\Ahea
"Evssstb"="C:\Documents and Settings\Owner\My Documents\?ppPatch\w?auboo
"Nwaovvm"="C:\WINDOWS\?sse
"Hfju"="C:\Program Files\??stem\?hkdsk.exe" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Ad
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Exif Launcher.lnk - C:\Program Files\FinePixViewer\QuickD
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56]
[HKEY_LOCAL_MACHINE\SOFTWA
"VhOEZx"= {A4F57159-0E5F-DBF3-075F-A
[HKEY_LOCAL_MACHINE\softwa
kbd__J.dll
[HKEY_LOCAL_MACHINE\softwa
rundll32.exe "C:\WINDOWS\mlkjji.dll",b
[HKEY_LOCAL_MACHINE\softwa
"C:\Program Files\Softwin\BitDefender1
[HKEY_LOCAL_MACHINE\softwa
"C:\Program Files\Softwin\BitDefender1
[HKEY_LOCAL_MACHINE\softwa
rundll32.exe "C:\WINDOWS\urpqqr.dll",fo
[HKEY_LOCAL_MACHINE\softwa
"WUSB54Gv4SVC"=2 (0x2)
"DomainService"=2 (0x2)
"VSSERV"=2 (0x2)
"bdss"=2 (0x2)
"LIVESRV"=2 (0x2)
"XCOMM"=2 (0x2)
R0 pwmdvpax;pwmdvpax;C:\WINDO
R2 AdobeActiveFileMonitor;Ado
R2 MLPTDR_J;MLPTDR_J;\??\C:\W
R2 PhotoshopElementsDeviceCon
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\
S3 WUSB54GV4SRV;Linksys Wireless-G USB Network Adapter Driver;C:\WINDOWS\system32
S4 WUSB54Gv4SVC;WUSB54Gv4SVC;
[HKEY_CURRENT_USER\softwar
\Shell\AutoRun\command - F:\LaunchU3.exe
[HKEY_CURRENT_USER\softwar
\Shell\AutoRun\command - F:\LaunchU3.exe
*Newly Created Service* - PWMDVPAX
.
Contents of the 'Scheduled Tasks' folder
"2007-11-07 01:49:03 C:\WINDOWS\Tasks\AppleSoft
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-13 05:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-12 18:17:43 C:\WINDOWS\Tasks\At10.job"
"2007-11-12 18:17:43 C:\WINDOWS\Tasks\At11.job"
"2007-11-12 18:17:43 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-12 18:17:43 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-12 18:17:43 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-12 19:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-12 20:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-12 21:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-12 22:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-12 23:00:01 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-13 06:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-13 00:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-14 01:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-13 02:00:01 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-13 03:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-13 04:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-13 05:00:00 C:\WINDOWS\Tasks\At25.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-13 06:00:00 C:\WINDOWS\Tasks\At26.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-13 07:00:00 C:\WINDOWS\Tasks\At27.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-13 08:00:00 C:\WINDOWS\Tasks\At28.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-13 09:00:00 C:\WINDOWS\Tasks\At29.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-13 07:00:00 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-13 10:00:00 C:\WINDOWS\Tasks\At30.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-13 11:00:00 C:\WINDOWS\Tasks\At31.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-12 18:17:43 C:\WINDOWS\Tasks\At32.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-12 18:17:43 C:\WINDOWS\Tasks\At33.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-12 18:17:43 C:\WINDOWS\Tasks\At34.job"
"2007-11-12 18:17:43 C:\WINDOWS\Tasks\At35.job"
"2007-11-12 18:17:43 C:\WINDOWS\Tasks\At36.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-12 18:17:43 C:\WINDOWS\Tasks\At37.job"
"2007-11-12 18:17:43 C:\WINDOWS\Tasks\At38.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-12 19:00:00 C:\WINDOWS\Tasks\At39.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-13 08:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-12 20:00:00 C:\WINDOWS\Tasks\At40.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-12 21:00:00 C:\WINDOWS\Tasks\At41.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-12 22:00:00 C:\WINDOWS\Tasks\At42.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-12 23:00:01 C:\WINDOWS\Tasks\At43.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-13 00:00:00 C:\WINDOWS\Tasks\At44.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-14 01:00:00 C:\WINDOWS\Tasks\At45.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-13 02:00:01 C:\WINDOWS\Tasks\At46.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-13 03:00:00 C:\WINDOWS\Tasks\At47.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-13 04:00:00 C:\WINDOWS\Tasks\At48.job"
- C:\WINDOWS\System32\Kwjv45
"2007-11-13 09:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-13 10:00:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-13 11:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-12 18:17:43 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-12 18:17:43 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\System32\wQm4bG
"2007-11-06 23:00:00 C:\WINDOWS\Tasks\Pareto UNS.job"
- C:\Program Files\Common Files\ParetoLogic\UUS\UUS.
.
**************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-13 20:05:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
.
Completion time: 2007-11-13 20:07:02 - machine was rebooted
.
--- E O F ---
Main Topics
Browse All Topics





by: IndiGenusPosted on 2007-11-13 at 16:35:02ID: 20276752
Sounds like Vundo.
mputer.com /sUBs/Beta /ComboFix. exe
Download and Run ComboFix
http://download.bleepingco
Disconnect from the Internet, than disable your Anti-virus and any real-time Anti-spyware monitors that are running.
Then double click Combofix.exe & follow the prompts.
When finished, it will produce a log for you. Upload that log in your next reply with a new HijackThis log. Upload to the following link and post the link to it back here.
http://www.ee-stuff.com
Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall.
Note 2: Remember to re-enable your Anti-virus and Anti-spyware before reconnecting to the Internet.