C:\Windows\System32\drivers\svchost.exe Is the TR/Dropper.Gen Trojan
C:\Windows\Nail.exe Is the TR/Crypt.ULPM.Gen Trojan
C:\documents and settings\josh\local settings\temp\yhrsxqic.exe Is the TR/Dldr.Swizzor.CO Trojan
C:\documents and settings\josh\local settings\temp\...\wupd.exe Is the TR/Dldr.Intexp.B Trojan
C:\documents and settings\josh\local settings\temp\...\wupt.exe Is the TR/Dldr.Intexp.A Trojan
Here is the DDS.txt:
DDS (Ver_09-02-01.01) - NTFSx86
Run by Josh at 0:13:01.78 on Fri 03/06/2009
Internet Explorer: 6.0.2800.1106 BrowserJavaVersion: 1.6.0_12
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.447.108 [GMT -8:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\System32\svchost.exe -k Akamai
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\Program Files\Common Files\CMEII\CMESys.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Documents and Settings\Josh\Application Data\Google\wcwdu16814728.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Common Files\GMT\GMT.exe
C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Josh\Desktop\dds.scr
============== Pseudo HJT Report ===============
uWindow Title = Microsoft Internet Explorer provided by Verizon Online
mDefault_Page_URL = hxxp://www.emachines.com
uSearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
uURLSearchHooks: H - No File
mWinlogon: Shell=Explorer.exe c:\windows\Nail.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: ngpw34.clsIS: {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - c:\windows\ngpw34.dll
BHO: IExplorr29.clsIS: {54ed9b49-81d1-4866-95a6-30f01de0047e} - c:\windows\iexplorr29.dll
BHO: {6558519b-bd79-9eac-2944-9eeba430d9b9} - c:\windows\system32\xdoclz.dll
{6bd9132b-b337-55be-d705-10550585736b}
BHO: {83de62e0-5805-11d8-9b25-00e04c60faf2} -
BHO: IExplorr26.clsIS: {90e34f98-e3e6-4cd7-a592-e964fed8af78} - c:\windows\iexplorr26.dll
BHO: IExplorr27.clsIS: {94326e3f-f51f-4863-a832-4acd0d7d4bc3} - c:\windows\iexplorr27.dll
BHO: IExplorr11.clsIS: {bc0d2038-2de5-4a6f-92bc-b18a3e0de32a} - c:\windows\iexplorr11.dll
BHO: {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - No File
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FlashFXP Helper for Internet Explorer: {e5a1691b-d188-4419-ad02-90002030b8ee} - c:\progra~1\flashfxp\IEFlash.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Search Help: {e8eaeb34-f7b5-4c55-87ff-720faf53d841} - CSearchHelpIEExtension Object
BHO: ngsw31.clsIS: {e9147a0a-a866-4214-b47c-da821891240f} - c:\windows\ngsw31.dll
TB: {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - No File
TB: {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\System32\browseui.dll
uRun: [cB79Rjj2V] oddnetsh.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Gpw] c:\windows\system32\l?gonui.exe
uRun: [MyEmoticons] c:\program files\myemoticons\MYEMOTICONS.EXE
uRun: [cdloader] "c:\documents and settings\josh\application data\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [SVCHOST.EXE] c:\windows\system32\drivers\svchost.exe
uRun: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\RegistryBooster.exe /S
mRun: [CHotkey] zHotkey.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [conscorr] c:\windows\conscorr.exe
mRun: [g] c:\windows\g.exe
mRun: [LzsvH9] c:\windows\LzsvH9.exe
mRun: [WildTangent CDA] "c:\program files\wildtangent\apps\cda\gamedrvr.exe" /startup "c:\program files\wildtangent\apps\cda\cdaEngine0500.dll"
mRun: [CMESys] "c:\program files\common files\cmeii\CMESys.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [RZO] c:\documents and settings\josh\local settings\temp\RZO.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [realtecks] "c:\documents and settings\josh\application data\google\wcwdu16814728.exe" 2
mRun: [avgnt] "c:\program files\avira\antivir personaledition classic\avgnt.exe" /min
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [g.exe] c:\windows\g.exe
mRun: [LzsvH9.exe] c:\windows\LzsvH9.exe
mRun: [RZO.exe] c:\documents and settings\josh\local settings\temp\RZO.exe
StartupFolder: c:\docume~1\josh\startm~1\programs\startup\openof~1.lnk - j:\program files\openoffice.org 2.4\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\reader 8.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~2.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\precis~1.lnk - c:\program files\precisiontime\PrecisionTime.exe
uPolicies-explorer: SpecifyDefaultButtons = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: Web Rebates - file://c:\program files\web_rebates\sy1150\tp1150\scri1150a.htm
IE: {120E090D-9136-4b78-8258-F0B44B4BD2AC} - c:\windows\system32\ms.exe
IE: {6224f700-cba3-4071-b251-47cb894244cd} - c:\program files\icq\ICQ.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - hxxp://www.addictivetechnologies.net/DM0/cab/ATPartners.cab
DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab
DPF: {13197ACE-6851-45C3-A7FF-C281324D5489} - hxxp://www.2nd-thought.com/files/install.exe
DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab28578.cab
DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - hxxp://toolbar.isearch.com/general/drm.cab
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - hxxp://imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
DPF: {5C7F15E1-F31A-44FD-AA1A-2EC63AAFFD3A} - hxxp://www.atelys.com/src/Speedup.ocx
DPF: {62360003-D8A7-418B-9DC6-2B9DE95273A0} - hxxp://fdl.msn.com/public/investor/v8/0326/ticker.cab
DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - hxxps://www.gamespyid.com/alaunch.cab
DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - hxxp://www.nick.com/common/groove/gx/GrooveAX27.cab
DPF: {8A8F3D75-6564-4599-A7DC-313B43A89E1D} - hxxp://www.kazaa.net.cn/digital/AdInstaller.ocx
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - hxxp://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} - hxxp://autos.msn.com/components/ocx/survid/MSSurVid.cab
DPF: {99802379-7362-40E2-9D28-8A3B9AF880B7} - hxxp://hotsearchbar.com/toolbar2/winhot32.cab
DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} - hxxp://messenger.zone.msn.com/binary/ZAxRcMgr.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38029.8977199074
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab28578.cab
DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} - hxxp://autos.msn.com/components/ocx/exterior/Outside.cab
DPF: {BD393C14-72AD-4790-A095-76522973D6B8} - hxxp://messenger.zone.msn.com/binary/Bankshot.cab28578.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} - hxxp://messenger.zone.msn.com/binary/WoF.cab28578.cab
DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} - hxxp://cabs.roings.com/cabs/mmed.cab
DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} - hxxp://messenger.zone.msn.com/binary/Chess.cab28578.cab
DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} - hxxp://www.gamespot.com/KDX22/download/kdx.cab
DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab28578.cab
TCP: {31F9B1E7-D1EE-4FA4-8673-AEBEA9063D6F} = 208.67.222.222,208.67.220.220
LSA: Notification Packages = scecli scecli scecli scecli scecli
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\josh\apee28~1\mozilla\firefox\profiles\k1uzx82q.default\
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
============= SERVICES / DRIVERS ===============
R0 avgntmgr;avgntmgr;c:\windows\system32\drivers\avgntmgr.sys [2009-2-28 22336]
R1 avgntdd;avgntdd;c:\windows\system32\drivers\avgntdd.sys [2009-2-28 45376]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2009-2-23 12800]
R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler;c:\program files\avira\antivir personaledition classic\sched.exe [2009-2-28 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard;c:\program files\avira\antivir personaledition classic\avguard.exe [2009-2-28 151297]
S2 .NET Connection Service;.NET Framework Service;c:\windows\svchost.exe --> c:\windows\svchost.exe [?]
S2 SvcProc;System Startup Service ;c:\windows\svcproc.exe [2002-6-15 6656]
S3 Ip6FwHlp;IPv6 Internet Connection Firewall;c:\windows\system32\svchost.exe -k netsvcs [2009-2-23 12800]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2008-12-23 50704]
S4 Nvshtwtx;Nvshtwtx; [x]
============== File Associations ===============
regfile="regedit.exe" "%1"
=============== Created Last 30 ================
2009-03-05 22:06 1,245 ----h--- c:\windows\g
2009-03-05 19:32 <DIR> --d----- c:\docume~1\josh\apee28~1\W Photo Studio Viewer
2009-02-28 21:19 <DIR> --d----- c:\program files\CCleaner
2009-02-28 21:18 <DIR> --d----- c:\program files\Trend Micro
2009-02-28 20:56 <DIR> --d----- c:\docume~1\josh\apee28~1\Uniblue
2009-02-28 20:56 <DIR> --d----- c:\program files\Uniblue
2009-02-28 20:55 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-02-28 20:24 <DIR> --d----- c:\program files\Sun
2009-02-28 20:24 410,984 a------- c:\windows\system32\deploytk.dll
2009-02-28 20:24 73,728 a------- c:\windows\system32\javacpl.cpl
2009-02-28 20:20 <DIR> --d----- c:\docume~1\josh\apee28~1\Inkscape
2009-02-28 20:02 <DIR> --d----- c:\program files\Avira
2009-02-28 20:02 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Avira
2009-02-28 19:35 <DIR> --d----- c:\documents and settings\josh\amaya
2009-02-28 19:34 <DIR> --d----- c:\program files\Amaya
2009-02-28 16:11 <DIR> --d----- C:\ATI
2009-02-28 03:53 <DIR> --d----- c:\program files\Cloud
2009-02-28 03:51 <DIR> --d----- c:\program files\common files\Akamai
2009-02-28 02:55 <DIR> --d----- c:\program files\Kuma Games
2009-02-28 00:41 <DIR> --d----- c:\program files\AnalogX
2009-02-28 00:07 28,673 a------- c:\windows\system32\drivers\svchost.exe
2009-02-27 22:11 <DIR> --d----- c:\program files\FlashFXP
2009-02-27 22:11 <DIR> --d----- c:\docume~1\alluse~1\applic~1\FlashFXP
2009-02-27 22:10 <DIR> --d----- c:\program files\LittleFighter2
2009-02-25 14:53 <DIR> --d----- c:\program files\WinPcap
2009-02-25 14:34 <DIR> --d----- c:\docume~1\josh\apee28~1\mjusbsp
2009-02-25 14:34 56,832 ac------ c:\windows\system32\dllcache\usbaudio.sys
2009-02-25 14:34 56,832 a------- c:\windows\system32\drivers\USBAUDIO.sys
2009-02-25 02:54 <DIR> --d----- c:\program files\Netscape
2009-02-25 02:52 <DIR> --d----- c:\program files\DivX
2009-02-25 02:45 1,409 a------- c:\windows\QTFont.for
2009-02-25 02:45 54,156 a---h--- c:\windows\QTFont.qfn
2009-02-23 16:11 480,256 a------- c:\windows\system32\dllcache\cintsetp.exe
2009-02-23 16:10 535,552 a------- c:\windows\system32\rpcrt4.dll
2009-02-23 14:43 595,968 -------- c:\windows\system32\_002878_.tmp.dll
2009-02-23 11:42 88,566 a------- c:\windows\system32\nvapps.xml
2009-02-23 11:10 <DIR> --d----- c:\program files\SystemRequirementsLab
2009-02-23 11:09 <DIR> --d----- c:\documents and settings\josh\.java
2009-02-23 02:11 31,768 a------- c:\windows\system32\wucltui.dll.mui
2009-02-23 02:11 23,576 a------- c:\windows\system32\wuaucpl.cpl.mui
2009-02-23 02:11 23,576 a------- c:\windows\system32\wuapi.dll.mui
2009-02-23 02:11 18,456 a------- c:\windows\system32\wuaueng.dll.mui
2009-02-22 20:52 <DIR> --d----- c:\documents and settings\josh\.thumbnails
2009-02-22 20:45 <DIR> --d----- c:\documents and settings\josh\.gimp-2.2
2009-02-22 18:13 <DIR> --d----- c:\documents and settings\josh\.schism
2009-02-22 18:11 <DIR> --d----- c:\program files\ASIO4ALL v2
2009-02-22 16:57 71,819 a------- c:\windows\hpdj6500.hi2
2009-02-22 16:57 7,251 a------- c:\windows\hpdj6500.bu2
2009-02-22 16:35 <DIR> --d----- c:\docume~1\josh\apee28~1\Warsow
2009-02-22 16:24 225,280 a------- c:\windows\system32\rewire.dll
2009-02-22 16:24 <DIR> --d----- c:\program files\VstPlugins
2009-02-22 16:24 1,294,336 a------- c:\windows\system32\vorbis.acm
2009-02-22 16:22 <DIR> --d----- c:\program files\Image-Line
2009-02-22 16:09 3,328 ac------ c:\windows\system32\dllcache\pciide.sys
2009-02-22 16:09 3,328 a------- c:\windows\system32\drivers\pciide.sys
2009-02-22 16:09 208,896 a------- c:\windows\system32\nvusmb.exe
2009-02-22 16:09 699 -------- c:\windows\system32\nvsmb.nvu
2009-02-22 16:08 208,896 a------- c:\windows\system32\nvumctl.exe
2009-02-22 16:08 1,217 -------- c:\windows\system32\nvmctl.nvu
2009-02-22 16:08 17,056 a------- c:\windows\system32\nvdisp.nvu
2009-02-22 16:08 <DIR> --d----- c:\windows\nview
==================== Find3M ====================
2008-12-23 07:35 281,104 a------- c:\windows\system32\wpcap.dll
2008-12-23 07:35 100,880 a------- c:\windows\system32\Packet.dll
2008-12-23 07:33 53,299 a------- c:\windows\system32\pthreadVC.dll
2008-12-10 16:33 200,704 a------- c:\windows\system32\dtu100.dll
2008-12-10 16:33 86,016 a------- c:\windows\system32\dpl100.dll
2008-12-08 18:28 593,920 a------- c:\windows\system32\dpuGUI11.dll
2008-12-08 18:28 344,064 a------- c:\windows\system32\dpus11.dll
2008-12-08 18:28 294,912 a------- c:\windows\system32\dpu11.dll
2008-12-08 18:28 57,344 a------- c:\windows\system32\dpv11.dll
2004-11-13 11:38 81,408 ---shr-- c:\docume~1\josh\apee28~1\rncr.exe
2004-06-04 19:31 168,753 a------- c:\docume~1\josh\apee28~1\tvmknwrd.dll
2004-05-02 11:09 905 a------- c:\program files\uninstal.log
2004-10-29 05:18 253,962 ---sh--- c:\windows\system32\Mkwwa.exe
============= FINISH: 0:13:37.67 ===============
I would deeply appreciate any help given,
Thanks