Here is combofix log:
ComboFix 08-02.03.1 - Tania Billah 2008-02-04 16:33:37.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.500 [GMT -8:00]
Running from: C:\Documents and Settings\Tania Billah\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tania Billah\Desktop\CFScript.txt
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
FILE
C:\WINDOWS\system32\jkkll.dll
C:\WINDOWS\system32\rravsqyp.dll
C:\WINDOWS\system32\vtstu.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-01-05 to 2008-02-05 )))))))))))))))))))))))))))))))
.
2008-02-04 10:33 . 2008-02-04 10:33 <DIR> d-------- C:\Program Files\Java
2008-02-04 10:33 . 2008-02-04 10:33 <DIR> d-------- C:\Program Files\Common Files\Java
2008-02-04 10:33 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-03 12:02 . 2008-02-03 12:45 4,050 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-03 12:01 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-02-03 12:01 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-02-03 12:01 . 2008-02-02 00:55 83,456 --a------ C:\WINDOWS\system32\VACFix.exe
2008-02-03 12:01 . 2008-01-27 14:37 81,920 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-02-03 12:01 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-02-03 12:01 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-02-03 10:58 . 2008-02-03 14:40 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-03 10:58 . 2008-02-03 14:40 <DIR> d-------- C:\Documents and Settings\Tania Billah\Application Data\SUPERAntiSpyware.com
2008-02-03 10:58 . 2008-02-03 10:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-02 23:45 . 2008-02-03 14:33 <DIR> d-------- C:\VundoFix Backups
2008-02-02 23:11 . 2008-02-02 23:11 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-01-24 14:21 . 2008-01-24 14:21 <DIR> dr------- C:\Documents and Settings\All Users\Application Data\SalesMon
2008-01-16 11:20 . 2008-02-04 11:23 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-16 11:20 . 2008-01-16 11:20 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-06 12:36 . 2008-01-06 12:36 <DIR> d-------- C:\Documents and Settings\Asif Billah\Application Data\SiteAdvisor
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-05 00:12 --------- d-----w C:\Documents and Settings\Tania Billah\Application Data\SiteAdvisor
2008-02-04 22:21 --------- d-----w C:\Program Files\Interaction Client .NET Edition
2008-02-03 22:40 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-03 20:19 146 -c--a-w C:\Documents and Settings\Asif Billah\Application Data\wklnhst.dat
2008-02-03 01:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-03 01:55 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-02-03 00:11 --------- d-----w C:\Program Files\McAfee
2008-01-28 22:33 --------- d-----w C:\Program Files\VIPdesk IM
2008-01-26 19:23 22,092 -c--a-w C:\Documents and Settings\Tania Billah\Application Data\wklnhst.dat
2008-01-06 21:10 --------- d-----w C:\Program Files\Common Files\NSV
2008-01-03 05:54 --------- d-----w C:\Program Files\SiteAdvisor
2008-01-02 14:08 --------- d-----w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-01-01 20:55 --------- d-----w C:\Program Files\McAfee.com
2008-01-01 20:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-01-01 20:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-01-01 20:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-01-01 20:51 --------- d-----w C:\Program Files\Common Files\McAfee
2007-12-26 04:22 --------- d-----w C:\Documents and Settings\Tania Billah\Application Data\CyberLink
2007-12-26 04:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Cyberlink
2007-12-26 04:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-26 04:08 --------- d-----w C:\Program Files\CyberLink
2007-12-26 04:04 --------- d-----w C:\Program Files\Digital Photo Navigator 1.5
2007-12-10 18:35 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-12-10 18:35 --------- d-----w C:\Documents and Settings\Tania Billah\Application Data\skypePM
2007-12-10 18:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-12-06 18:24 --------- d-----w C:\Program Files\XtenNetworksInc
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ------w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-29 01:50 722,176 ----a-w C:\Documents and Settings\Tania Billah\gotomypc_428.exe
2007-07-11 21:20 6,736 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:00 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"NoAds"="C:\Program Files\NoAds\NoAds.exe" [2007-11-23 23:25 151552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 01:56 761947]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-16 18:35 397312 C:\WINDOWS\stsystra.exe]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-12-15 07:44 839680]
"ShowLOMControl"="1 (0x1)" []
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 17:29 49152]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-04-05 13:53 98304]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 07:44 81920]
"Athan"="C:\Program Files\Athan\Athan.exe" [2006-05-23 03:32 974848]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-01-25 13:07 185896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06 40048]
"AIMPro"="C:\Program Files\AIM\AIM Pro\aimpro.exe" [ ]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-10-18 17:04 802816]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 16:58 696320]
"EverioService"="C:\Program Files\CyberLink\PCM4Everio\EverioService.exe" [2006-11-22 21:10 151552]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 15:30 152144]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2007-08-24 13:57 36640]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe [2007-05-24 08:40:38 1524776]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-04-05 13:49:11 24576]
R1 ATMDLC;Attachmate DLC Protocol;C:\WINDOWS\system32\DRIVERS\atmdlc.sys [2004-06-14 08:00]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-26 02:30:01 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (TANIABILLAH-Asif Billah).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
"2008-01-01 20:49:49 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-01-01 20:49:47 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-04 16:35:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\NoAds\NoAds.dll
.
Completion time: 2008-02-04 16:36:14
ComboFix-quarantined-files.txt 2008-02-05 00:36:06
ComboFix2.txt 2008-02-04 18:05:31
ComboFix3.txt 2008-02-04 05:50:44
.
2008-02-01 15:05:19 --- E O F ---
And here is bitdefender log:
BitDefender Online Scanner
Scan report generated at: Mon, Feb 04, 2008 - 17:41:46
Scan path: C:\;D:\;
Statistics
Time
00:48:34
Files
200919
Folders
6417
Boot Sectors
4
Archives
4806
Packed Files
10663
Results
Identified Viruses
7
Infected Files
24
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
24
Engines Info
Virus Definitions
978926
Engine build
AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)
Scan plugins
16
Archive plugins
41
Unpack plugins
7
E-mail plugins
6
System plugins
5
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\QooBox\Quarantine\C\WINDOWS\system32\drfikupw.dll.vir
Infected with: Trojan.Vundo.DXU
C:\QooBox\Quarantine\C\WINDOWS\system32\drfikupw.dll.vir
Deleted
C:\QooBox\Quarantine\C\WINDOWS\system32\fyamwzsg.dll.vir
Infected with: Trojan.Vundo.DWB
C:\QooBox\Quarantine\C\WINDOWS\system32\fyamwzsg.dll.vir
Deleted
C:\QooBox\Quarantine\C\WINDOWS\system32\jkkifcc.dll.vir
Infected with: Trojan.Vundo.DXE
C:\QooBox\Quarantine\C\WINDOWS\system32\jkkifcc.dll.vir
Deleted
C:\QooBox\Quarantine\C\WINDOWS\system32\kvpbwgai.dll.vir
Infected with: Trojan.Vundo.DXV
C:\QooBox\Quarantine\C\WINDOWS\system32\kvpbwgai.dll.vir
Deleted
C:\QooBox\Quarantine\catchme2008-02-03_214710.90.zip=>fyamwzsg.dll
Infected with: Trojan.Vundo.DWB
C:\QooBox\Quarantine\catchme2008-02-03_214710.90.zip=>fyamwzsg.dll
Deleted
C:\QooBox\Quarantine\catchme2008-02-03_214710.90.zip
Updated
C:\VundoFix Backups\ajbivmwo.dll.bad
Infected with: Trojan.Vundo.DXU
C:\VundoFix Backups\ajbivmwo.dll.bad
Deleted
C:\VundoFix Backups\cbxusrq.dll.bad
Infected with: Trojan.Vundo.DXE
C:\VundoFix Backups\cbxusrq.dll.bad
Deleted
C:\VundoFix Backups\cgylccev.dll.bad
Infected with: Trojan.Vundo.DWB
C:\VundoFix Backups\cgylccev.dll.bad
Deleted
C:\VundoFix Backups\dcrypjla.dll.bad
Infected with: Trojan.Vundo.DWB
C:\VundoFix Backups\dcrypjla.dll.bad
Deleted
C:\VundoFix Backups\emqmetyd.dll.bad
Infected with: Trojan.Vundo.DWB
C:\VundoFix Backups\emqmetyd.dll.bad
Deleted
C:\VundoFix Backups\fblaivdi.dll.bad
Infected with: Trojan.Vundo.DVC
C:\VundoFix Backups\fblaivdi.dll.bad
Disinfection failed
C:\VundoFix Backups\fblaivdi.dll.bad
Deleted
C:\VundoFix Backups\fernrfkb.dll.bad
Infected with: Trojan.Vundo.DXU
C:\VundoFix Backups\fernrfkb.dll.bad
Deleted
C:\VundoFix Backups\foxhunot.dll.bad
Infected with: Trojan.Vundo.DXU
C:\VundoFix Backups\foxhunot.dll.bad
Deleted
C:\VundoFix Backups\fyamwzsg.dll.bad
Infected with: Trojan.Vundo.DWB
C:\VundoFix Backups\fyamwzsg.dll.bad
Deleted
C:\VundoFix Backups\homqrkqf.dll.bad
Infected with: Trojan.Vundo.DXV
C:\VundoFix Backups\homqrkqf.dll.bad
Deleted
C:\VundoFix Backups\jkkifcc.dll.bad
Infected with: Trojan.Vundo.DXE
C:\VundoFix Backups\jkkifcc.dll.bad
Deleted
C:\VundoFix Backups\jxfojrch.dll.bad
Infected with: Trojan.Vundo.DXS
C:\VundoFix Backups\jxfojrch.dll.bad
Deleted
C:\VundoFix Backups\kvpbwgai.dll.bad
Infected with: Trojan.Vundo.DXV
C:\VundoFix Backups\kvpbwgai.dll.bad
Deleted
C:\VundoFix Backups\pkqdhaio.dll.bad
Infected with: Trojan.Vundo.DXV
C:\VundoFix Backups\pkqdhaio.dll.bad
Deleted
C:\VundoFix Backups\qvewlkey.dll.bad
Infected with: Trojan.Vundo.DXU
C:\VundoFix Backups\qvewlkey.dll.bad
Deleted
C:\VundoFix Backups\sdiudkso.dll.bad
Infected with: Trojan.Vundo.DWB
C:\VundoFix Backups\sdiudkso.dll.bad
Deleted
C:\VundoFix Backups\ssttt.dll.bad
Infected with: Trojan.Vundo.DXG
C:\VundoFix Backups\ssttt.dll.bad
Deleted
C:\VundoFix Backups\xbfprbfb.dll.bad
Infected with: Trojan.Vundo.DWB
C:\VundoFix Backups\xbfprbfb.dll.bad
Deleted
C:\VundoFix Backups\xunvvrab.dll.bad
Infected with: Trojan.Vundo.DVC
C:\VundoFix Backups\xunvvrab.dll.bad
Disinfection failed
C:\VundoFix Backups\xunvvrab.dll.bad
Deleted
kml